Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0010 ✕
Download CSV Show ATT&CK heatmapExternal Sharing was turned on for Google Drive Informational Identity Threat Module, SaaS Threat Detection 3 variations
An identity has modified Google Drive sharing settings and allowed external sharing.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Transfer Data to Cloud Account (T1537)Required data: Google Workspace Audit LogsDetector tags: Google WorkspaceAttacker's goals: Adversaries may exfiltrate data, such as sensitive documents.Investigative actions: Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). check the new setting details. Follow further actions done by the account.Variations
External Sharing was turned on for Google Drive by a non Google Workspace administrative user from an unusual ASN
Low overridden
An identity has modified Google Drive sharing settings and allowed external sharing. overridden
External Sharing was turned on for Google Drive by a non Google Workspace administrative user
Low overridden
An identity has modified Google Drive sharing settings and allowed external sharing. overridden
External Sharing was turned on for Google Drive from an unusual ASN
Low overridden
An identity has modified Google Drive sharing settings and allowed external sharing. overridden