Analytics BIOC Informational

A third-party application was authorized to access the Google Workspace APIs

A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Initial Access (TA0001) Privilege Escalation (TA0004)
ATT&CK techniques: Valid Accounts (T1078)
Detector tags: Google Workspace
Attacker's goals:

Gain access to Google Workspace data and services. Collect confidential information from Google Workspace. Compromise user accounts and data.

Investigative actions:

Check which account was granted access to the Domain API. Identify the source IP address of the request. Verify the legitimacy of the request.

Test period:
N/A (single event)
Deduplication:
5 Days