OS Login

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for oslogin.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNN
google.cloud.oslogin.dataplane.OsLoginDataPlaneService.CheckPolicyChecks whether a principal is authorized to log in to a VM via OS Login; emitted on every SSH login attempt.data_accessNY
google.cloud.oslogin.dataplane.OsLoginDataPlaneService.ContinueSessionRecords completion of an OS Login two-factor authentication challenge.data_accessNY
google.cloud.oslogin.dataplane.OsLoginDataPlaneService.StartSessionRecords initiation of an OS Login two-factor authentication challenge.data_accessNN
google.cloud.oslogin.OsLoginService.ImportSshPublicKeyUploads an SSH public key to a user's OS Login profile (DATA_WRITE).data_accessNN
google.cloud.oslogin.controlplane.regional.OsLoginRegionalService.SignSshPublicKeySigns a short-lived SSH certificate for an OS Login user in the regional control plane (ADMIN_READ).data_accessNN
google.cloud.oslogin.OsLoginService.GetLoginProfileReads a user's OS Login profile (POSIX accounts, SSH keys). Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs.not_auditedNN
google.cloud.oslogin.OsLoginService.DeletePosixAccountRemoves a POSIX account from a user's OS Login profile. Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs.not_auditedNN

any: oslogin.googleapis.com (any method)

#
ServiceName
oslogin.googleapis.com

Description

Catch-all entry for oslogin.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

google.cloud.oslogin.dataplane.OsLoginDataPlaneService.CheckPolicy: Check policy

#
ServiceName
oslogin.googleapis.com

Description

Checks whether a principal is authorized to log in to a VM via OS Login; emitted on every SSH login attempt.

Data Access audit logs are disabled by default.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

google.cloud.oslogin.dataplane.OsLoginDataPlaneService.ContinueSession: Continue session

#
ServiceName
oslogin.googleapis.com

Description

Records completion of an OS Login two-factor authentication challenge.

Data Access audit logs are disabled by default.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

google.cloud.oslogin.dataplane.OsLoginDataPlaneService.StartSession: Start session

#
ServiceName
oslogin.googleapis.com

Description

Records initiation of an OS Login two-factor authentication challenge.

Data Access audit logs are disabled by default.

google.cloud.oslogin.OsLoginService.ImportSshPublicKey: Import SSH public key

#
ServiceName
oslogin.googleapis.com

Description

Uploads an SSH public key to a user's OS Login profile (DATA_WRITE).

Data Access audit logs are disabled by default.

google.cloud.oslogin.controlplane.regional.OsLoginRegionalService.SignSshPublicKey: Sign SSH public key

#
ServiceName
oslogin.googleapis.com

Description

Signs a short-lived SSH certificate for an OS Login user in the regional control plane (ADMIN_READ).

Data Access audit logs are disabled by default.

google.cloud.oslogin.OsLoginService.GetLoginProfile: Get login profile

#
ServiceName
oslogin.googleapis.com

Description

Reads a user's OS Login profile (POSIX accounts, SSH keys). Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs.

google.cloud.oslogin.OsLoginService.DeletePosixAccount: Delete POSIX account

#
ServiceName
oslogin.googleapis.com

Description

Removes a POSIX account from a user's OS Login profile. Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs.