Access Context Manager
| methodName | Description | Log type | Sample | Rule |
|---|---|---|---|---|
| any | Catch-all entry for accesscontextmanager.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation. | activity | N | Y |
| google. | Commit the dry-run spec for all the Service Perimeters in an Access Policy. A commit operation on a Service Perimeter involves copying its spec field to that Service Perimeter's status field. | activity | N | N |
| google. | Creates an access level. | activity | N | N |
| google. | Creates an access policy. This method fails if the organization already has an access policy. The long-running operation has a successful status after the access policy propagates to long-lasting storage. | activity | N | N |
| google. | Creates a Service Perimeter. | activity | N | N |
| google. | Deletes an Access Level based on the resource name. | activity | N | N |
| google. | Deletes an access policy based on the resource name. | activity | N | N |
| google. | Deletes a Service Perimeter based on the resource name. | activity | N | N |
| google. | Updates an Access Level. The long-running operation from this RPC has a successful status after the changes to the Access Level propagate to long-lasting storage. | activity | N | N |
| google. | Updates an access policy. The long-running operation from this RPC has a successful status after the changes to the access policy propagate to long-lasting storage. | activity | N | N |
| google. | Updates a Service Perimeter. The long-running operation from this RPC has a successful status after the changes to the Service Perimeter propagate to long-lasting storage. | activity | N | N |
any: accesscontextmanager.googleapis.com (any method)
#Description
Catch-all entry for accesscontextmanager.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1098
google.identity.accesscontextmanager.AccessContextManager.CommitServicePerimeters: Commit service perimeters
#Description
Commit the dry-run spec for all the Service Perimeters in an Access Policy. A commit operation on a Service Perimeter involves copying its spec field to that Service Perimeter's status field.
google.identity.accesscontextmanager.AccessContextManager.CreateAccessLevel: Create access level
#Description
Creates an access level.
google.identity.accesscontextmanager.AccessContextManager.CreateAccessPolicy: Create access policy
#Description
Creates an access policy. This method fails if the organization already has an access policy. The long-running operation has a successful status after the access policy propagates to long-lasting storage.
google.identity.accesscontextmanager.AccessContextManager.CreateServicePerimeter: Create service perimeter
#Description
Creates a Service Perimeter.
google.identity.accesscontextmanager.AccessContextManager.DeleteAccessLevel: Delete access level
#Description
Deletes an Access Level based on the resource name.
google.identity.accesscontextmanager.AccessContextManager.DeleteAccessPolicy: Delete access policy
#Description
Deletes an access policy based on the resource name.
google.identity.accesscontextmanager.AccessContextManager.DeleteServicePerimeter: Delete service perimeter
#Description
Deletes a Service Perimeter based on the resource name.
google.identity.accesscontextmanager.AccessContextManager.UpdateAccessLevel: Update access level
#Description
Updates an Access Level. The long-running operation from this RPC has a successful status after the changes to the Access Level propagate to long-lasting storage.
google.identity.accesscontextmanager.AccessContextManager.UpdateAccessPolicy: Update access policy
#Description
Updates an access policy. The long-running operation from this RPC has a successful status after the changes to the access policy propagate to long-lasting storage.
google.identity.accesscontextmanager.AccessContextManager.UpdateServicePerimeter: Update service perimeter
#Description
Updates a Service Perimeter. The long-running operation from this RPC has a successful status after the changes to the Service Perimeter propagate to long-lasting storage.