Analytics BIOC
Informational
✕
An app was added to the Google Workspace trusted OAuth apps list
An identity added an OAuth app to the Google Workspace trusted OAuth apps list.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Google Workspace Audit Logs
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Modify Authentication Process (T1556)
Detector tags: Google Workspace
Attacker's goals:
Malicious OAuth apps can be used to request elevated permissions or to impersonate another user.
Investigative actions:
Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the app that was added to the trusted apps list looks suspicious. Follow further actions done by the account.
- Test period:
- N/A (single event)
- Deduplication:
- 2 Days
2 variations:
- An unusual app was added to the Google Workspace trusted OAuth apps list Low (parent: Informational)
- An app was added to the Google Workspace trusted OAuth apps list by a non-administrative identity Low (parent: Informational)