GCP project-wide SSH keys block removed
ID:gcp_project_wide_ssh_block_removed
Data type:Google Cloud Platform
Severity:
Informational
MITRE ATT&CK:TA0005:T1556
Description
AlphaSOC detected the removal of the "block-project-ssh-keys" metadata from a Google Compute Engine instance. This setting, when enabled, prevents project-wide SSH keys from accessing the instance. Removing this block allows all project-wide SSH keys to authenticate to the instance, significantly increasing the attack surface if any project-wide keys are compromised.