Cloud Deployment Manager

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for deploymentmanager.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNY
deploymentmanager.deployments.insertCreates a deployment and actuates its configuration; gated by deploymentmanager.deployments.create, a documented privilege-escalation path. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.activityNN
deploymentmanager.deployments.updateReplaces a deployment's full configuration. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.activityNN
deploymentmanager.deployments.patchApplies a partial update to a deployment's configuration. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.activityNN
deploymentmanager.deployments.deleteDeletes a deployment and, depending on policy, its actuated resources. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.activityNN
deploymentmanager.deployments.stopCancels an in-progress deployment operation. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.activityNN
deploymentmanager.deployments.cancelPreviewCancels a deployment preview before it is committed. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.activityNN
deploymentmanager.deployments.setIamPolicySets the IAM policy on a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.activityNN
deploymentmanager.deployments.getReads a single deployment's configuration and state. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.data_accessNN
deploymentmanager.deployments.listLists deployments in a project. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.data_accessNN
deploymentmanager.resources.listLists the resources actuated by a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.data_accessNN
deploymentmanager.manifests.getReads the expanded manifest (fully resolved resource templates) for a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.data_accessNN

any: deploymentmanager.googleapis.com (any method)

#
ServiceName
deploymentmanager.googleapis.com

Description

Catch-all entry for deploymentmanager.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
protoPayload.authorizationInfo (panther rule field)is_not_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

deploymentmanager.deployments.insert: Insert deployment

#
ServiceName
deploymentmanager.googleapis.com

Description

Creates a deployment and actuates its configuration; gated by deploymentmanager.deployments.create, a documented privilege-escalation path. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

deploymentmanager.deployments.update: Update deployment

#
ServiceName
deploymentmanager.googleapis.com

Description

Replaces a deployment's full configuration. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

deploymentmanager.deployments.patch: Patch deployment

#
ServiceName
deploymentmanager.googleapis.com

Description

Applies a partial update to a deployment's configuration. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

deploymentmanager.deployments.delete: Delete deployment

#
ServiceName
deploymentmanager.googleapis.com

Description

Deletes a deployment and, depending on policy, its actuated resources. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

deploymentmanager.deployments.stop: Stop deployment

#
ServiceName
deploymentmanager.googleapis.com

Description

Cancels an in-progress deployment operation. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

deploymentmanager.deployments.cancelPreview: Cancel deployment preview

#
ServiceName
deploymentmanager.googleapis.com

Description

Cancels a deployment preview before it is committed. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

deploymentmanager.deployments.setIamPolicy: Set deployment IAM policy

#
ServiceName
deploymentmanager.googleapis.com

Description

Sets the IAM policy on a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

deploymentmanager.deployments.get: Get deployment

#
ServiceName
deploymentmanager.googleapis.com

Description

Reads a single deployment's configuration and state. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

Data Access audit logs are disabled by default.

deploymentmanager.deployments.list: List deployments

#
ServiceName
deploymentmanager.googleapis.com

Description

Lists deployments in a project. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

Data Access audit logs are disabled by default.

deploymentmanager.resources.list: List deployment resources

#
ServiceName
deploymentmanager.googleapis.com

Description

Lists the resources actuated by a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

Data Access audit logs are disabled by default.

deploymentmanager.manifests.get: Get manifest

#
ServiceName
deploymentmanager.googleapis.com

Description

Reads the expanded manifest (fully resolved resource templates) for a deployment. Cloud Deployment Manager reached end of support on 2026-03-31; the method no longer generates new audit entries and is cataloged for historical log analysis.

Data Access audit logs are disabled by default.