google.ssh-serialport.v1.connect
google.ssh-serialport.v1.connect
Event
Records a serial-console connection through the SSH serial-port service. This reaches a serial port, not necessarily an authenticated guest shell.
Security Context
Unauthorized remote access can support T1021.004. Serial access can avoid the guest sshd path, but console enablement, organization policy, SSH authentication to the gateway, and guest login requirements still apply. No command execution is shown, so T1059 was removed.
Log Source
Cloud Audit Logs: ssh-serialport.googleapis.com, method google.ssh-serialport.v1.connect. Inspect the connection outcome and corresponding disconnect record. The audit session does not provide a guest command transcript.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Confirm approval and effective serial-console controls for the target VM.
- Inspect connection status and correlate the disconnect record by operation.id.
- Review guest authentication and command evidence before claiming a shell or execution.
Sample Event
Synthetic scenario. The synthetic connection succeeds to SerialPort/1. The service name, request type, target path, and session correlation follow documented serial-console fields; no prior key injection or guest login is established.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.6", "requestAttributes": { "time": "2026-04-15T16:08:42.221987654Z", "auth": {} } }, "serviceName": "ssh-serialport.googleapis.com", "methodName": "google.ssh-serialport.v1.connect", "resourceName": "projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001/SerialPort/1", "request": { "@type": "type.googleapis.com/google.compute.SerialConsoleSessionBegin", "username": "draco_malfoy" }, "status": { "message": "Connection succeeded." } }, "insertId": "evt001111110111", "resource": { "type": "gce_instance", "labels": { "project_id": "fantasticlogs-prod", "zone": "us-central1-a", "instance_id": "6100000000000000011" } }, "timestamp": "2026-04-15T16:08:42.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T16:08:42.821987Z", "operation": { "id": "synthetic-serial-session-001", "producer": "ssh-serialport.googleapis.com", "first": true }}Sources
MITRE ATT&CK Mapping
Tactics: Lateral Movement
- T1021.004 — SSH — Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.