Analytics BIOC Informational

A Google Workspace identity performed an unusual admin console activity

A Google Workspace identity performed an admin console activity for the first time.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Valid Accounts (T1078)
Detector tags: Google Workspace
Attacker's goals:

To do.

Investigative actions:

Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the changes that were made look suspicious. Follow further actions done by the account.

Test period:
N/A (single event)
Deduplication:
2 Days
1 variation:
  • A non-administrative Google Workspace identity performed an unusual admin console activity Informational