google.cloud.securitycenter.v1.SecurityCenter.SetMute
google.cloud.securitycenter.v1.SecurityCenter.SetMute
Event
SetMute changes a finding’s mute state without deleting it or stopping the detector. Muted findings are hidden from the default console view but remain queryable.
Security Context
Unauthorized muting can impair detection workflows (T1685). Notification exports can still include muted findings when their filters match; muting alone does not silence every alert pipeline. Findings can be addressed at organization, folder, or project scope depending on the API and configuration.
Log Source
Cloud Audit Logs: securitycenter.googleapis.com, method google.cloud.securitycenter.v1.SecurityCenter.SetMute. Data Access (DATA_WRITE). Enable applicable Security Command Center audit logging and inspect the finding’s parent scope; this example uses an organization log.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Inspect the exact finding, original mute state, actor, scope/location, and reason for the change.
- Review notification/export filters and downstream handling of mute state before claiming alert suppression.
- Query muted findings, check related changes, and distinguish finding state ACTIVE from mute state MUTED.
Sample Event
Synthetic scenario. The v1 example sets one organization-scoped finding to MUTED while it remains ACTIVE. A synthetic finding ID/category is used; no prior key-creation incident or custom-role grant is established.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.scc.findings.set-mute invocation-id/90000000000000000000001111110001 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T13:51:48.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "securitycenter.googleapis.com", "methodName": "google.cloud.securitycenter.v1.SecurityCenter.SetMute", "authorizationInfo": [ { "resource": "organizations/555123456789/sources/100000000000000000111/findings/0123456789abcdef0123456789abcdef", "permission": "securitycenter.findings.setMute", "granted": true, "resourceAttributes": {} } ], "resourceName": "organizations/555123456789/sources/100000000000000000111/findings/0123456789abcdef0123456789abcdef", "request": { "@type": "type.googleapis.com/google.cloud.securitycenter.v1.SetMuteRequest", "name": "organizations/555123456789/sources/100000000000000000111/findings/0123456789abcdef0123456789abcdef", "mute": "MUTED" }, "response": { "@type": "type.googleapis.com/google.cloud.securitycenter.v1.Finding", "name": "organizations/555123456789/sources/100000000000000000111/findings/0123456789abcdef0123456789abcdef", "parent": "organizations/555123456789/sources/100000000000000000111", "category": "SYNTHETIC_FINDING", "state": "ACTIVE", "severity": "HIGH", "mute": "MUTED", "muteUpdateTime": "2026-04-15T13:51:48.321987Z" } }, "insertId": "evt001111110001", "resource": { "type": "organization", "labels": { "organization_id": "555123456789" } }, "timestamp": "2026-04-15T13:51:48.421987Z", "severity": "INFO", "logName": "organizations/555123456789/logs/cloudaudit.googleapis.com%2Fdata_access", "receiveTimestamp": "2026-04-15T13:51:48.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...