Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1556 ✕

Download CSV Show ATT&CK heatmap
  • An app was removed from a blocked list in Google Workspace Informational Identity Threat Module, SaaS Threat Detection 3 variations

    An identity removed an app from Google Workspace blocked OAuth or third-party apps list.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    2 Days
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Modify Authentication Process (T1556)
    Required data: Google Workspace Audit Logs
    Detector tags: Google Workspace
    Attacker's goals: Malicious OAuth Apps can be used to request elevated permissions or to impersonate another user.
    Investigative actions: Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the app that was removed from the trusted apps list looks suspicious. Follow further actions done by the account.

    Variations

    An app was removed from a blocked list in Google Workspace by a suspicious identity

    Low overridden

    An identity removed an app from Google Workspace blocked OAuth or third-party apps list. overridden

    An app was removed from a blocked list in Google Workspace by a non Google Workspace administrative user

    Low overridden

    An identity removed an app from Google Workspace blocked OAuth or third-party apps list. overridden

    An app was removed from a blocked list in Google Workspace from an unusual ASN

    Low overridden

    An identity removed an app from Google Workspace blocked OAuth or third-party apps list. overridden