Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1484 ✕

Download CSV Show ATT&CK heatmap
  • Google Workspace third-party application's security settings were changed Informational Identity Threat Module, SaaS Threat Detection 3 variations

    An identity changed Google Workspace third-party application's security settings.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    2 Days
    ATT&CK tactics: Privilege Escalation (TA0004)
    ATT&CK techniques: Domain or Tenant Policy Modification (T1484)
    Required data: Google Workspace Audit Logs
    Detector tags: Google Workspace
    Attacker's goals: Malicious apps can be used to access the organization's Google data.
    Investigative actions: Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.

    Variations

    Google Workspace third-party application's security settings were changed by a suspicious identity

    Low overridden

    An identity changed Google Workspace third-party application's security settings. overridden

    Google Workspace third-party application's security settings were changed from an unusual ASN

    Low overridden

    An identity changed Google Workspace third-party application's security settings. overridden

    Google Workspace third-party application's security settings were changed by a non Google Workspace administrative user

    Informational overridden

    An identity changed Google Workspace third-party application's security settings. overridden