Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1562 ✕

Download CSV Show ATT&CK heatmap
  • Security object deletion in Google Workspace Admin Console Informational Identity Threat Module, SaaS Threat Detection 1 variation

    A security object was deleted in Google Workspace Admin Console.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
    Required data: Google Workspace Audit Logs
    Detector tags: Google Workspace
    Attacker's goals: Adversaries may modify or disable security rules to avoid detection of their activities.
    Investigative actions: Investigate the security object name deleted and whether it was intended. Check if the user was recently granted new elevated permissions that allowed them to delete security rules. Follow other administrative or suspicious actions performed by this user around the same time.

    Variations

    Security object deletion in Google Workspace Admin Console for the first time

    Low overridden

    A security object was deleted in Google Workspace Admin Console. overridden