Skip to content

google.ssh-serialport.v1.connect

GCP

google.ssh-serialport.v1.connect

service: GCP - SSH Serial Port
techniques:

Event

Records a serial-console connection through the SSH serial-port service. This reaches a serial port, not necessarily an authenticated guest shell.

Security Context

Unauthorized remote access can support T1021.004. Serial access can avoid the guest sshd path, but console enablement, organization policy, SSH authentication to the gateway, and guest login requirements still apply. No command execution is shown, so T1059 was removed.

Log Source

Cloud Audit Logs: ssh-serialport.googleapis.com, method google.ssh-serialport.v1.connect. Inspect the connection outcome and corresponding disconnect record. The audit session does not provide a guest command transcript.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Confirm approval and effective serial-console controls for the target VM.
  3. Inspect connection status and correlate the disconnect record by operation.id.
  4. Review guest authentication and command evidence before claiming a shell or execution.

Sample Event

Synthetic scenario. The synthetic connection succeeds to SerialPort/1. The service name, request type, target path, and session correlation follow documented serial-console fields; no prior key injection or guest login is established.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.6",
"requestAttributes": {
"time": "2026-04-15T16:08:42.221987654Z",
"auth": {}
}
},
"serviceName": "ssh-serialport.googleapis.com",
"methodName": "google.ssh-serialport.v1.connect",
"resourceName": "projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001/SerialPort/1",
"request": {
"@type": "type.googleapis.com/google.compute.SerialConsoleSessionBegin",
"username": "draco_malfoy"
},
"status": {
"message": "Connection succeeded."
}
},
"insertId": "evt001111110111",
"resource": {
"type": "gce_instance",
"labels": {
"project_id": "fantasticlogs-prod",
"zone": "us-central1-a",
"instance_id": "6100000000000000011"
}
},
"timestamp": "2026-04-15T16:08:42.421987Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"receiveTimestamp": "2026-04-15T16:08:42.821987Z",
"operation": {
"id": "synthetic-serial-session-001",
"producer": "ssh-serialport.googleapis.com",
"first": true
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Lateral Movement

Techniques:
  • T1021.004 — SSH — Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.