Cloud Deployment Manager
| methodName | Description | Log type | Sample | Rule |
|---|---|---|---|---|
| any | Catch-all entry for deploymentmanager.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation. | activity | N | Y |
| deploymentmanager. | Creates a deployment and actuates its configuration; gated by deploymentmanager.deployments.create, a documented privilege-escalation path. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | activity | N | N |
| deploymentmanager. | Replaces a deployment's full configuration. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | activity | N | N |
| deploymentmanager. | Applies a partial update to a deployment's configuration. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | activity | N | N |
| deploymentmanager. | Deletes a deployment and, depending on policy, its actuated resources. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | activity | N | N |
| deploymentmanager. | Cancels an in-progress deployment operation. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | activity | N | N |
| deploymentmanager. | Cancels a deployment preview before it is committed. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | activity | N | N |
| deploymentmanager. | Sets the IAM policy on a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | activity | N | N |
| deploymentmanager. | Reads a single deployment's configuration and state. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | data_access | N | N |
| deploymentmanager. | Lists deployments in a project. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | data_access | N | N |
| deploymentmanager. | Lists the resources actuated by a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | data_access | N | N |
| deploymentmanager. | Reads the expanded manifest (fully resolved resource templates) for a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis. | data_access | N | N |
any: deploymentmanager.googleapis.com (any method)
#Description
Catch-all entry for deploymentmanager.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
protoPayload.authorizationInfo (panther rule field) | is_not_null | | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1548
deploymentmanager.deployments.insert: Insert deployment
#Description
Creates a deployment and actuates its configuration; gated by deploymentmanager.deployments.create, a documented privilege-escalation path. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
deploymentmanager.deployments.update: Update deployment
#Description
Replaces a deployment's full configuration. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
deploymentmanager.deployments.patch: Patch deployment
#Description
Applies a partial update to a deployment's configuration. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
deploymentmanager.deployments.delete: Delete deployment
#Description
Deletes a deployment and, depending on policy, its actuated resources. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
deploymentmanager.deployments.stop: Stop deployment
#Description
Cancels an in-progress deployment operation. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
deploymentmanager.deployments.cancelPreview: Cancel deployment preview
#Description
Cancels a deployment preview before it is committed. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
deploymentmanager.deployments.setIamPolicy: Set deployment IAM policy
#Description
Sets the IAM policy on a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
deploymentmanager.deployments.get: Get deployment
#Description
Reads a single deployment's configuration and state. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
Data Access audit logs are disabled by default.
deploymentmanager.deployments.list: List deployments
#Description
Lists deployments in a project. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
Data Access audit logs are disabled by default.
deploymentmanager.resources.list: List deployment resources
#Description
Lists the resources actuated by a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
Data Access audit logs are disabled by default.
deploymentmanager.manifests.get: Get manifest
#Description
Reads the expanded manifest (fully resolved resource templates) for a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.
Data Access audit logs are disabled by default.