Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1485 ✕

Download CSV Show ATT&CK heatmap
  • Massive files deletion in Google Drive Informational Identity Threat Module 1 variation

    A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Data Destruction (T1485)
    Required data: Google Workspace Audit Logs
    Detector tags: Data Detection & Response, Google Workspace
    Attacker's goals: An attacker may delete files from a SaaS service to wipe data from the organization.
    Investigative actions: Investigate the source account and verify if it was compromised or performed an authorized activity. Review the files that were deleted to determine if they contain sensitive or critical data. Monitor the account for any further suspicious actions.

    Variations

    Massive files deletion in Google Drive with suspicious parameters

    Low overridden

    A suspicious user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped. overridden