Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAn app was added to the Google Workspace trusted OAuth apps list Informational Identity Threat Module, SaaS Threat Detection 2 variations
An identity added an OAuth app to the Google Workspace trusted OAuth apps list.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 2 Days
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Modify Authentication Process (T1556)Required data: Google Workspace Audit LogsDetector tags: Google WorkspaceAttacker's goals: Malicious OAuth apps can be used to request elevated permissions or to impersonate another user.Investigative actions: Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the app that was added to the trusted apps list looks suspicious. Follow further actions done by the account.Variations
An unusual app was added to the Google Workspace trusted OAuth apps list
Low overridden
An identity added an OAuth app to the Google Workspace trusted OAuth apps list. overridden
An app was added to the Google Workspace trusted OAuth apps list by a non-administrative identity
Low overridden
An identity added an OAuth app to the Google Workspace trusted OAuth apps list. overridden