Analytics BIOC Informational

A Google Workspace identity created, assigned or modified a role

A Google Workspace identity created, assigned or modified a delegated admin role.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Valid Accounts (T1078)
Detector tags: Google Workspace
Attacker's goals:

An adversary may create, assign or modify a role to elevate the permissions of other user accounts and persist in their target's environment.

Investigative actions:

Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check the identity's role designation in the organization. Follow further actions done by the account.

Test period:
N/A (single event)
Deduplication:
2 Days
3 variations:
  • A non-administrative Google Workspace identity created, assigned or modified a role from an unusual ASN Low (parent: Informational)
  • A non-administrative Google Workspace identity created, assigned or modified a role Low (parent: Informational)
  • A Google Workspace identity created, assigned or modified a role from an unusual ASN Low (parent: Informational)