Skip to content

google.cloud.securitycenter.v1.SecurityCenter.SetMute

GCP

google.cloud.securitycenter.v1.SecurityCenter.SetMute

service: GCP - Security Command Center
techniques:

Event

SetMute changes a finding’s mute state without deleting it or stopping the detector. Muted findings are hidden from the default console view but remain queryable.

Security Context

Unauthorized muting can impair detection workflows (T1685). Notification exports can still include muted findings when their filters match; muting alone does not silence every alert pipeline. Findings can be addressed at organization, folder, or project scope depending on the API and configuration.

Log Source

Cloud Audit Logs: securitycenter.googleapis.com, method google.cloud.securitycenter.v1.SecurityCenter.SetMute. Data Access (DATA_WRITE). Enable applicable Security Command Center audit logging and inspect the finding’s parent scope; this example uses an organization log.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Inspect the exact finding, original mute state, actor, scope/location, and reason for the change.
  3. Review notification/export filters and downstream handling of mute state before claiming alert suppression.
  4. Query muted findings, check related changes, and distinguish finding state ACTIVE from mute state MUTED.

Sample Event

Synthetic scenario. The v1 example sets one organization-scoped finding to MUTED while it remains ACTIVE. A synthetic finding ID/category is used; no prior key-creation incident or custom-role grant is established.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.scc.findings.set-mute invocation-id/90000000000000000000001111110001 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T13:51:48.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "securitycenter.googleapis.com",
"methodName": "google.cloud.securitycenter.v1.SecurityCenter.SetMute",
"authorizationInfo": [
{
"resource": "organizations/555123456789/sources/100000000000000000111/findings/0123456789abcdef0123456789abcdef",
"permission": "securitycenter.findings.setMute",
"granted": true,
"resourceAttributes": {}
}
],
"resourceName": "organizations/555123456789/sources/100000000000000000111/findings/0123456789abcdef0123456789abcdef",
"request": {
"@type": "type.googleapis.com/google.cloud.securitycenter.v1.SetMuteRequest",
"name": "organizations/555123456789/sources/100000000000000000111/findings/0123456789abcdef0123456789abcdef",
"mute": "MUTED"
},
"response": {
"@type": "type.googleapis.com/google.cloud.securitycenter.v1.Finding",
"name": "organizations/555123456789/sources/100000000000000000111/findings/0123456789abcdef0123456789abcdef",
"parent": "organizations/555123456789/sources/100000000000000000111",
"category": "SYNTHETIC_FINDING",
"state": "ACTIVE",
"severity": "HIGH",
"mute": "MUTED",
"muteUpdateTime": "2026-04-15T13:51:48.321987Z"
}
},
"insertId": "evt001111110001",
"resource": {
"type": "organization",
"labels": {
"organization_id": "555123456789"
}
},
"timestamp": "2026-04-15T13:51:48.421987Z",
"severity": "INFO",
"logName": "organizations/555123456789/logs/cloudaudit.googleapis.com%2Fdata_access",
"receiveTimestamp": "2026-04-15T13:51:48.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.