OS Login
| methodName | Description | Log type | Sample | Rule |
|---|---|---|---|---|
| any | Catch-all entry for oslogin.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation. | activity | N | N |
| google. | Checks whether a principal is authorized to log in to a VM via OS Login; emitted on every SSH login attempt. | data_access | N | Y |
| google. | Records completion of an OS Login two-factor authentication challenge. | data_access | N | Y |
| google. | Records initiation of an OS Login two-factor authentication challenge. | data_access | N | N |
| google. | Uploads an SSH public key to a user's OS Login profile (DATA_WRITE). | data_access | N | N |
| google. | Signs a short-lived SSH certificate for an OS Login user in the regional control plane (ADMIN_READ). | data_access | N | N |
| google. | Reads a user's OS Login profile (POSIX accounts, SSH keys). Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs. | not_audited | N | N |
| google. | Removes a POSIX account from a user's OS Login profile. Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs. | not_audited | N | N |
any: oslogin.googleapis.com (any method)
#Description
Catch-all entry for oslogin.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
google.cloud.oslogin.dataplane.OsLoginDataPlaneService.CheckPolicy: Check policy
#Description
Checks whether a principal is authorized to log in to a VM via OS Login; emitted on every SSH login attempt.
Data Access audit logs are disabled by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
google.cloud.oslogin.dataplane.OsLoginDataPlaneService.ContinueSession: Continue session
#Description
Records completion of an OS Login two-factor authentication challenge.
Data Access audit logs are disabled by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Panther #
google.cloud.oslogin.dataplane.OsLoginDataPlaneService.StartSession: Start session
#Description
Records initiation of an OS Login two-factor authentication challenge.
Data Access audit logs are disabled by default.
google.cloud.oslogin.OsLoginService.ImportSshPublicKey: Import SSH public key
#Description
Uploads an SSH public key to a user's OS Login profile (DATA_WRITE).
Data Access audit logs are disabled by default.
google.cloud.oslogin.controlplane.regional.OsLoginRegionalService.SignSshPublicKey: Sign SSH public key
#Description
Signs a short-lived SSH certificate for an OS Login user in the regional control plane (ADMIN_READ).
Data Access audit logs are disabled by default.
google.cloud.oslogin.OsLoginService.GetLoginProfile: Get login profile
#Description
Reads a user's OS Login profile (POSIX accounts, SSH keys). Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs.
google.cloud.oslogin.OsLoginService.DeletePosixAccount: Delete POSIX account
#Description
Removes a POSIX account from a user's OS Login profile. Not audit-logged: Google excludes this method from Cloud Audit Logs as a high-volume data-plane operation, so no audit log entry ever records it. Detections cannot source this operation from Cloud Audit Logs.