SecurityCenter.UpdateOrganizationSettings (deprecated)
SecurityCenter.UpdateOrganizationSettings (deprecated)
Event
UpdateOrganizationSettings is a deprecated v1 API for organization-level settings. Its assetDiscoveryConfig can include or exclude projects from legacy asset discovery; it is not a general switch for all current Security Command Center detectors.
Security Context
Unauthorized coverage changes can support T1685 where effective defense impairment is demonstrated. Confirm which services still consume this legacy configuration. The event does not establish deletion of historical assets, universal loss of findings, or an earlier mute operation.
Log Source
Cloud Audit Logs: securitycenter.googleapis.com, method google.cloud.securitycenter.v1.SecurityCenter.UpdateOrganizationSettings. Admin Activity. Inspect status and resulting state; a granted permission alone does not establish success. This legacy method remains listed in the audit reference; the example is organization-scoped.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Effective caller, delegation where present, and request context. |
protoPayload.methodName, resourceName | Operation and exact target; distinguish versions/generations and resource scope. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, serviceData | Settings, returned state, or policy deltas where present; compare old state separately. |
timestamp, logName | Timing, owning resource, and audit stream. |
What to Investigate
- Confirm the observed change and compare it with the approved workflow.
- Verify the organization, updateMask, old/new inclusion mode, project list, caller, and approval.
- Determine the actual effect of this deprecated setting in the deployed SCC configuration and inspect service-specific detector settings.
- Check subsequent asset/finding coverage and independent monitoring; distinguish an accepted configuration change from a proven detection outage.
Sample Event
Synthetic scenario. The example changes assetDiscoveryConfig to exclude fantasticlogs-prod while enableAssetDiscovery remains true. It illustrates the documented legacy schema; it does not establish that current SCC protection is disabled.
Exact optional fields, payload disclosure, and protobuf serialization remain unverified against captured logs. These synthetic examples do not establish an attack chain and are not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "synthetic-client/1.0", "requestAttributes": { "time": "2026-04-15T13:58:18.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "securitycenter.googleapis.com", "methodName": "google.cloud.securitycenter.v1.SecurityCenter.UpdateOrganizationSettings", "authorizationInfo": [ { "resource": "organizations/555123456789/organizationSettings", "permission": "securitycenter.organizationsettings.update", "granted": true, "resourceAttributes": {} } ], "resourceName": "organizations/555123456789/organizationSettings", "request": { "@type": "type.googleapis.com/google.cloud.securitycenter.v1.UpdateOrganizationSettingsRequest", "organizationSettings": { "name": "organizations/555123456789/organizationSettings", "enableAssetDiscovery": true, "assetDiscoveryConfig": { "projectIds": [ "fantasticlogs-prod" ], "inclusionMode": "EXCLUDE" } }, "updateMask": "assetDiscoveryConfig" }, "response": { "@type": "type.googleapis.com/google.cloud.securitycenter.v1.OrganizationSettings", "name": "organizations/555123456789/organizationSettings", "enableAssetDiscovery": true, "assetDiscoveryConfig": { "projectIds": [ "fantasticlogs-prod" ], "inclusionMode": "EXCLUDE" } } }, "insertId": "evt010000000100", "resource": { "type": "organization", "labels": { "organization_id": "555123456789" } }, "timestamp": "2026-04-15T13:58:18.421987Z", "severity": "NOTICE", "logName": "organizations/555123456789/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T13:58:18.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...