Serial Console SSH Gateway

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for ssh-serialport.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNN
google.ssh-serialport.connectRecords a connection attempt to a VM's serial console through the ssh-serialport.googleapis.com gateway; access is IAM-gated, not firewall-gated. In real records the serviceName is region-prefixed (for example us-central1-ssh-serialport.googleapis.com).activityNY
google.ssh-serialport.disconnectRecorded at the end of a serial console session, symmetric with the connect entry. In real records the serviceName is region-prefixed (for example us-central1-ssh-serialport.googleapis.com).activityNN

any: ssh-serialport.googleapis.com (any method)

#
ServiceName
ssh-serialport.googleapis.com

Description

Catch-all entry for ssh-serialport.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

google.ssh-serialport.connect: Connect

#
ServiceName
ssh-serialport.googleapis.com

Description

Records a connection attempt to a VM's serial console through the ssh-serialport.googleapis.com gateway; access is IAM-gated, not firewall-gated. In real records the serviceName is region-prefixed (for example us-central1-ssh-serialport.googleapis.com).

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

google.ssh-serialport.disconnect: Disconnect

#
ServiceName
ssh-serialport.googleapis.com

Description

Recorded at the end of a serial console session, symmetric with the connect entry. In real records the serviceName is region-prefixed (for example us-central1-ssh-serialport.googleapis.com).