Analytics BIOC Informational

An app was removed from a blocked list in Google Workspace

An identity removed an app from Google Workspace blocked OAuth or third-party apps list.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Modify Authentication Process (T1556)
Detector tags: Google Workspace
Attacker's goals:

Malicious OAuth Apps can be used to request elevated permissions or to impersonate another user.

Investigative actions:

Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the app that was removed from the trusted apps list looks suspicious. Follow further actions done by the account.

Test period:
N/A (single event)
Deduplication:
2 Days
3 variations:
  • An app was removed from a blocked list in Google Workspace by a suspicious identity Low (parent: Informational)
  • An app was removed from a blocked list in Google Workspace by a non Google Workspace administrative user Low (parent: Informational)
  • An app was removed from a blocked list in Google Workspace from an unusual ASN Low (parent: Informational)