Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1078 ✕

Download CSV Show ATT&CK heatmap
  • A Google Workspace identity performed an unusual admin console activity Informational Identity Threat Module, SaaS Threat Detection 1 variation

    A Google Workspace identity performed an admin console activity for the first time.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    2 Days
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: Google Workspace Audit Logs
    Detector tags: Google Workspace
    Attacker's goals: To do.
    Investigative actions: Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the changes that were made look suspicious. Follow further actions done by the account.

    Variations

    A non-administrative Google Workspace identity performed an unusual admin console activity

    Informational overridden

    A Google Workspace identity performed an admin console activity for the first time. overridden