Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0004 ✕
Download CSV Show ATT&CK heatmapA Google Workspace service was configured as unrestricted Informational Identity Threat Module, SaaS Threat Detection 3 variations
An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 2 Days
ATT&CK tactics: Privilege Escalation (TA0004)ATT&CK techniques: Domain or Tenant Policy Modification (T1484)Required data: Google Workspace Audit LogsDetector tags: Google WorkspaceAttacker's goals: Malicious apps can be used to access the organization's Google data.Investigative actions: Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.Variations
A Google Workspace service was configured as unrestricted by a suspicious identity
Low overridden
An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services. overridden
A Google Workspace service was configured as unrestricted from an unusual ASN
Low overridden
An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services. overridden
A Google Workspace service was configured as unrestricted by a non-administrative identity
Informational overridden
An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services. overridden