Serial Console SSH Gateway
| methodName | Description | Log type | Sample | Rule |
|---|---|---|---|---|
| any | Catch-all entry for ssh-serialport.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation. | activity | N | N |
| google. | Records a connection attempt to a VM's serial console through the ssh-serialport.googleapis.com gateway; access is IAM-gated, not firewall-gated. In real records the serviceName is region-prefixed (for example us-central1-ssh-serialport.googleapis.com). | activity | N | Y |
| google. | Recorded at the end of a serial console session, symmetric with the connect entry. In real records the serviceName is region-prefixed (for example us-central1-ssh-serialport.googleapis.com). | activity | N | N |
any: ssh-serialport.googleapis.com (any method)
#Description
Catch-all entry for ssh-serialport.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
google.ssh-serialport.connect: Connect
#Description
Records a connection attempt to a VM's serial console through the ssh-serialport.googleapis.com gateway; access is IAM-gated, not firewall-gated. In real records the serviceName is region-prefixed (for example us-central1-ssh-serialport.googleapis.com).
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
google.ssh-serialport.disconnect: Disconnect
#Description
Recorded at the end of a serial console session, symmetric with the connect entry. In real records the serviceName is region-prefixed (for example us-central1-ssh-serialport.googleapis.com).