Access Context Manager

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for accesscontextmanager.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNY
google.identity.accesscontextmanager.AccessContextManager.CommitServicePerimetersCommit the dry-run spec for all the Service Perimeters in an Access Policy. A commit operation on a Service Perimeter involves copying its spec field to that Service Perimeter's status field.activityNN
google.identity.accesscontextmanager.AccessContextManager.CreateAccessLevelCreates an access level.activityNN
google.identity.accesscontextmanager.AccessContextManager.CreateAccessPolicyCreates an access policy. This method fails if the organization already has an access policy. The long-running operation has a successful status after the access policy propagates to long-lasting storage.activityNN
google.identity.accesscontextmanager.AccessContextManager.CreateServicePerimeterCreates a Service Perimeter.activityNN
google.identity.accesscontextmanager.AccessContextManager.DeleteAccessLevelDeletes an Access Level based on the resource name.activityNN
google.identity.accesscontextmanager.AccessContextManager.DeleteAccessPolicyDeletes an access policy based on the resource name.activityNN
google.identity.accesscontextmanager.AccessContextManager.DeleteServicePerimeterDeletes a Service Perimeter based on the resource name.activityNN
google.identity.accesscontextmanager.AccessContextManager.UpdateAccessLevelUpdates an Access Level. The long-running operation from this RPC has a successful status after the changes to the Access Level propagate to long-lasting storage.activityNN
google.identity.accesscontextmanager.AccessContextManager.UpdateAccessPolicyUpdates an access policy. The long-running operation from this RPC has a successful status after the changes to the access policy propagate to long-lasting storage.activityNN
google.identity.accesscontextmanager.AccessContextManager.UpdateServicePerimeterUpdates a Service Perimeter. The long-running operation from this RPC has a successful status after the changes to the Service Perimeter propagate to long-lasting storage.activityNN

any: accesscontextmanager.googleapis.com (any method)

#
ServiceName
accesscontextmanager.googleapis.com

Description

Catch-all entry for accesscontextmanager.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • GCP Access Policy Deleted source medium: Detects when an access policy that is applied to a GCP cloud resource is deleted. An adversary would be able to remove access policies to gain access to a GCP cloud resource.T1098

google.identity.accesscontextmanager.AccessContextManager.CommitServicePerimeters: Commit service perimeters

#
ServiceName
accesscontextmanager.googleapis.com

Description

Commit the dry-run spec for all the Service Perimeters in an Access Policy. A commit operation on a Service Perimeter involves copying its spec field to that Service Perimeter's status field.

google.identity.accesscontextmanager.AccessContextManager.CreateAccessLevel: Create access level

#
ServiceName
accesscontextmanager.googleapis.com

Description

Creates an access level.

google.identity.accesscontextmanager.AccessContextManager.CreateAccessPolicy: Create access policy

#
ServiceName
accesscontextmanager.googleapis.com

Description

Creates an access policy. This method fails if the organization already has an access policy. The long-running operation has a successful status after the access policy propagates to long-lasting storage.

google.identity.accesscontextmanager.AccessContextManager.CreateServicePerimeter: Create service perimeter

#
ServiceName
accesscontextmanager.googleapis.com

Description

Creates a Service Perimeter.

google.identity.accesscontextmanager.AccessContextManager.DeleteAccessLevel: Delete access level

#
ServiceName
accesscontextmanager.googleapis.com

Description

Deletes an Access Level based on the resource name.

google.identity.accesscontextmanager.AccessContextManager.DeleteAccessPolicy: Delete access policy

#
ServiceName
accesscontextmanager.googleapis.com

Description

Deletes an access policy based on the resource name.

google.identity.accesscontextmanager.AccessContextManager.DeleteServicePerimeter: Delete service perimeter

#
ServiceName
accesscontextmanager.googleapis.com

Description

Deletes a Service Perimeter based on the resource name.

google.identity.accesscontextmanager.AccessContextManager.UpdateAccessLevel: Update access level

#
ServiceName
accesscontextmanager.googleapis.com

Description

Updates an Access Level. The long-running operation from this RPC has a successful status after the changes to the Access Level propagate to long-lasting storage.

google.identity.accesscontextmanager.AccessContextManager.UpdateAccessPolicy: Update access policy

#
ServiceName
accesscontextmanager.googleapis.com

Description

Updates an access policy. The long-running operation from this RPC has a successful status after the changes to the access policy propagate to long-lasting storage.

google.identity.accesscontextmanager.AccessContextManager.UpdateServicePerimeter: Update service perimeter

#
ServiceName
accesscontextmanager.googleapis.com

Description

Updates a Service Perimeter. The long-running operation from this RPC has a successful status after the changes to the Service Perimeter propagate to long-lasting storage.