users.sshPublicKeys.patch
users.sshPublicKeys.patch
Event
users.sshPublicKeys.patch invokes UpdateSshPublicKey on a key identified by its SHA-256 fingerprint. The update mask selects changed fields; an expiry change can matter even when the fingerprint is unchanged.
Security Context
Unauthorized key-lifetime changes can support persistence (T1098.004). A key update does not grant new VM permissions or prove SSH use. Requiring OS Login alone does not restrict key registration to an approved workflow; the former unspecified organization-policy recommendation was removed.
Log Source
Google explicitly lists google.cloud.oslogin.v1.OsLoginService.UpdateSshPublicKey among methods that do not generate Cloud Audit Logs. Enabling Data Access logging does not create coverage for an explicitly unlogged method. Use authorized profile snapshots, workflow records, and guest authentication logs as complementary evidence.
Key Fields
| Field | Investigation value |
|---|---|
Key resource/fingerprint | Profile data identifies the key under users/{user}/sshPublicKeys/{fingerprint}; this is not a native audit field. |
expirationTimeUsec | Compare the key lifetime even when its fingerprint is unchanged. |
Snapshot collection time and guest authentication | Bound the observed change interval and investigate use; snapshots alone do not identify the caller. |
What to Investigate
- Confirm the observed change and compare it with the approved workflow.
- Compare authorized profile snapshots for key material, fingerprints, and expiration times, not fingerprints alone.
- Confirm that collection has permission to read the relevant profiles; do not assume arbitrary cross-user polling is allowed.
- Correlate VM authentication and approved key-management records; assess IAM, key expiry, and authentication controls separately.
Sample Event
No native Cloud Audit Log example is provided because Google explicitly lists UpdateSshPublicKey as not generating audit logs. An expiry extension can be investigated through authorized before/after profile snapshots and guest evidence, but snapshots do not identify the API caller or exact change time.
Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1098.004 — SSH Authorized Keys — Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</...