users.importSshPublicKey
users.importSshPublicKey
Event
ImportSshPublicKey adds a key to a user’s OS Login profile and returns an ImportSshPublicKeyResponse containing loginProfile. Key registration alone does not grant VM IAM access or prove an SSH session.
Security Context
Unauthorized key registration can support persistence (T1098.004), subject to effective OS Login permissions, account state, key expiry, VM configuration, and network/authentication controls. No cross-user modification or identity-laundering capability is assumed.
Log Source
Current coverage is unresolved in Google’s documentation: the English audit reference updated October 2, 2026 omits ImportSshPublicKey from both its audited and non-audited method lists; the German reference updated September 15 still lists it as Data Access (DATA_WRITE). Do not infer either guaranteed logging or guaranteed absence from this discrepancy. Validate method emission and applicable audit configuration before relying on a detection.
Key Fields
| Field | Investigation value |
|---|---|
Profile owner and caller | Conceptual attribution to establish through authorized collection; no native audit fields are guaranteed here. |
SSH key fingerprint and expirationTimeUsec | Compare key identity and lifetime in profile data; possession of the private key is separate. |
loginProfile | Documented response container; returned profile content is not evidence of VM login. |
What to Investigate
- Confirm the observed change and compare it with the approved workflow.
- Resolve the authenticated account and profile owner, and establish authority for any action on another user’s profile.
- Compare profile keys and expiration times through an authorized workflow; identify eligible VMs and required OS Login permissions.
- Validate current audit coverage in your environment, then correlate guest authentication before claiming access or lateral movement.
Sample Event
Synthetic scenario. The former purported audit record was replaced with a conceptual import summary for Draco’s own profile. It avoids invented cross-user access, malformed SSH material, a fabricated fingerprint, and an incorrect response wrapper. Key bytes are omitted; this is not a native audit event or executable API request.
{ "illustrationType": "Conceptual import summary, not a native audit event or API request", "apiMethod": "users.importSshPublicKey", "profileOwner": "draco@fantasticlogs.cloud", "projectId": "fantasticlogs-prod", "keyMaterial": "omitted", "responseContainer": "loginProfile"}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1098.004 — SSH Authorized Keys — Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</...