Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • An app was added to Google Marketplace Informational Identity Threat Module, SaaS Threat Detection 3 variations

    An app was added to the Google Workspace Marketplace.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Remote Access Tools (T1219)
    Required data: Google Workspace Audit Logs
    Detector tags: Google Workspace
    Attacker's goals: An adversary may add a malicious application to an organization's Google Workspace domain to maintain a presence in their target's organization and steal data.
    Investigative actions: Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate the new app that was added to Google workspace Marketplace. Follow further actions done by the account.

    Variations

    An app was added to Google Marketplace by a non-administrative identity

    Informational overridden

    An app was added to the Google Workspace Marketplace. overridden

    An app was added to Google Marketplace from an unusual ASN

    Low overridden

    An app was added to the Google Workspace Marketplace. overridden

    An unusual app was added to Google Marketplace

    Low overridden

    An app was added to the Google Workspace Marketplace. overridden