Skip to content

users.importSshPublicKey

GCP

users.importSshPublicKey

service: GCP - OS Login
tactics:
techniques:

Event

ImportSshPublicKey adds a key to a user’s OS Login profile and returns an ImportSshPublicKeyResponse containing loginProfile. Key registration alone does not grant VM IAM access or prove an SSH session.

Security Context

Unauthorized key registration can support persistence (T1098.004), subject to effective OS Login permissions, account state, key expiry, VM configuration, and network/authentication controls. No cross-user modification or identity-laundering capability is assumed.

Log Source

Current coverage is unresolved in Google’s documentation: the English audit reference updated October 2, 2026 omits ImportSshPublicKey from both its audited and non-audited method lists; the German reference updated September 15 still lists it as Data Access (DATA_WRITE). Do not infer either guaranteed logging or guaranteed absence from this discrepancy. Validate method emission and applicable audit configuration before relying on a detection.

Key Fields

FieldInvestigation value
Profile owner and callerConceptual attribution to establish through authorized collection; no native audit fields are guaranteed here.
SSH key fingerprint and expirationTimeUsecCompare key identity and lifetime in profile data; possession of the private key is separate.
loginProfileDocumented response container; returned profile content is not evidence of VM login.

What to Investigate

  1. Confirm the observed change and compare it with the approved workflow.
  2. Resolve the authenticated account and profile owner, and establish authority for any action on another user’s profile.
  3. Compare profile keys and expiration times through an authorized workflow; identify eligible VMs and required OS Login permissions.
  4. Validate current audit coverage in your environment, then correlate guest authentication before claiming access or lateral movement.

Sample Event

Synthetic scenario. The former purported audit record was replaced with a conceptual import summary for Draco’s own profile. It avoids invented cross-user access, malformed SSH material, a fabricated fingerprint, and an incorrect response wrapper. Key bytes are omitted; this is not a native audit event or executable API request.

{
"illustrationType": "Conceptual import summary, not a native audit event or API request",
"apiMethod": "users.importSshPublicKey",
"profileOwner": "draco@fantasticlogs.cloud",
"projectId": "fantasticlogs-prod",
"keyMaterial": "omitted",
"responseContainer": "loginProfile"
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1098.004 — SSH Authorized Keys — Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.