Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1484 ✕

Download CSV Show ATT&CK heatmap
  • A domain was added to the trusted domains list Low Identity Threat Module, SaaS Threat Detection 2 variations

    A domain was added to the Google Workspace trusted domains list.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses (T1562) Domain or Tenant Policy Modification: Trust Modification (T1484.002)
    Required data: Google Workspace Audit Logs
    Detector tags: Google Workspace
    Attacker's goals: An adversary may add a trusted domain to collect and exfiltrate data from their target's organization with less restrictive security controls.
    Investigative actions: Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate the new domain in the trusted domains list. Follow further actions done by the account.

    Variations

    A domain was added to the trusted domains list by a non Google Workspace administrative user

    Low overridden

    A domain was added to the Google Workspace trusted domains list. overridden

    A domain was added to the trusted domains list from an unusual ASN

    Low overridden

    A domain was added to the Google Workspace trusted domains list. overridden