Analytics BIOC Informational

A Google Workspace user was added to a group

A user added another user to a Google Workspace group.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098)
Detector tags: Google Workspace
Attacker's goals:

Adversaries may manipulate accounts and groups to maintain access to victim systems.

Investigative actions:

Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the user was added to a sensitive group. Follow further actions done by the account.

Test period:
N/A (single event)
Deduplication:
5 Days