Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1537 ✕

Download CSV Show ATT&CK heatmap
  • External Sharing was turned on for Google Drive Informational Identity Threat Module, SaaS Threat Detection 3 variations

    An identity has modified Google Drive sharing settings and allowed external sharing.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Transfer Data to Cloud Account (T1537)
    Required data: Google Workspace Audit Logs
    Detector tags: Google Workspace
    Attacker's goals: Adversaries may exfiltrate data, such as sensitive documents.
    Investigative actions: Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). check the new setting details. Follow further actions done by the account.

    Variations

    External Sharing was turned on for Google Drive by a non Google Workspace administrative user from an unusual ASN

    Low overridden

    An identity has modified Google Drive sharing settings and allowed external sharing. overridden

    External Sharing was turned on for Google Drive by a non Google Workspace administrative user

    Low overridden

    An identity has modified Google Drive sharing settings and allowed external sharing. overridden

    External Sharing was turned on for Google Drive from an unusual ASN

    Low overridden

    An identity has modified Google Drive sharing settings and allowed external sharing. overridden