Analytics BIOC Informational

A Google Workspace identity used the security investigation tool

A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Information Repositories (T1213) Email Collection (T1114)
Detector tags: Google Workspace
Attacker's goals:

Access sensitive data.

Investigative actions:

Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Determine what data was accessed using the security investigation tool.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • A suspicious Google Workspace identity used the security investigation tool Low (parent: Informational)