Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1531 ✕

Download CSV Show ATT&CK heatmap
  • A third-party application's access to the Google Workspace domain's resources was revoked Informational Identity Threat Module, SaaS Threat Detection

    An identity removed a third-party application's access to Google Workspace domain's resources.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Account Access Removal (T1531)
    Required data: Google Workspace Audit Logs
    Detector tags: Google Workspace
    Attacker's goals: An attacker might remove an application to impair the environment.
    Investigative actions: Check the Google Workspace Application settings to determine which actions were triggered. Investigate the source of the request and the user associated with it. Review the access control policies to determine if the removal of the application is allowed.