Skip to content

users.sshPublicKeys.patch

GCP

users.sshPublicKeys.patch

service: GCP - OS Login
tactics:
techniques:

Event

users.sshPublicKeys.patch invokes UpdateSshPublicKey on a key identified by its SHA-256 fingerprint. The update mask selects changed fields; an expiry change can matter even when the fingerprint is unchanged.

Security Context

Unauthorized key-lifetime changes can support persistence (T1098.004). A key update does not grant new VM permissions or prove SSH use. Requiring OS Login alone does not restrict key registration to an approved workflow; the former unspecified organization-policy recommendation was removed.

Log Source

Google explicitly lists google.cloud.oslogin.v1.OsLoginService.UpdateSshPublicKey among methods that do not generate Cloud Audit Logs. Enabling Data Access logging does not create coverage for an explicitly unlogged method. Use authorized profile snapshots, workflow records, and guest authentication logs as complementary evidence.

Key Fields

FieldInvestigation value
Key resource/fingerprintProfile data identifies the key under users/{user}/sshPublicKeys/{fingerprint}; this is not a native audit field.
expirationTimeUsecCompare the key lifetime even when its fingerprint is unchanged.
Snapshot collection time and guest authenticationBound the observed change interval and investigate use; snapshots alone do not identify the caller.

What to Investigate

  1. Confirm the observed change and compare it with the approved workflow.
  2. Compare authorized profile snapshots for key material, fingerprints, and expiration times, not fingerprints alone.
  3. Confirm that collection has permission to read the relevant profiles; do not assume arbitrary cross-user polling is allowed.
  4. Correlate VM authentication and approved key-management records; assess IAM, key expiry, and authentication controls separately.

Sample Event

No native Cloud Audit Log example is provided because Google explicitly lists UpdateSshPublicKey as not generating audit logs. An expiry extension can be investigated through authorized before/after profile snapshots and guest evidence, but snapshots do not identify the API caller or exact change time.

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1098.004 — SSH Authorized Keys — Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.