Unexpected GCP API calls indicating Compute Engine serial port enabled
ID:gcp_compute_engine_serial_port_enabled_anomaly
Data type:Google Cloud Platform
Severity:
Informational
- Medium
MITRE ATT&CK:TA0005:T1562
Description
AlphaSOC detected that serial port access was enabled on a Google Cloud Compute Engine instance. The serial console provides an out-of-band management channel for interactive access to instances, commonly used for troubleshooting boot issues, debugging unresponsive instances, and recovery operations. Enabling this feature unexpectedly may indicate an attacker establishing an alternative access method.
Impact
Serial port access provides an additional channel to interact with instances that may not be as closely monitored as standard SSH or RDP connections. Attackers may enable this feature to conduct activities through a less scrutinized path, potentially evading detection.
Severity
| Severity | Condition |
|---|---|
Informational | Serial port access enabled |
Low | Serial port access enabled with anomalous patterns |
Medium | Serial port access enabled in suspicious context |