Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0001 ✕ technique: T1078 ✕
Download CSV Show ATT&CK heatmapA third-party application was authorized to access the Google Workspace APIs Informational Identity Threat Module, SaaS Threat Detection
A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Initial Access (TA0001) Privilege Escalation (TA0004)ATT&CK techniques: Valid Accounts (T1078)Required data: Google Workspace Audit LogsDetector tags: Google WorkspaceAttacker's goals: Gain access to Google Workspace data and services. Collect confidential information from Google Workspace. Compromise user accounts and data.Investigative actions: Check which account was granted access to the Domain API. Identify the source IP address of the request. Verify the legitimacy of the request.