Analytics BIOC
Informational
✕
A Google Workspace service was configured as unrestricted
An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Google Workspace Audit Logs
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Domain or Tenant Policy Modification (T1484)
Detector tags: Google Workspace
Attacker's goals:
Malicious apps can be used to access the organization's Google data.
Investigative actions:
Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.
- Test period:
- N/A (single event)
- Deduplication:
- 2 Days
3 variations:
- A Google Workspace service was configured as unrestricted by a suspicious identity Low (parent: Informational)
- A Google Workspace service was configured as unrestricted from an unusual ASN Low (parent: Informational)
- A Google Workspace service was configured as unrestricted by a non-administrative identity Informational