Analytics BIOC
Informational
✕
Chrome OS Remote Access policy was modified in Google Workspace
A user modified Chrome OS Remote Access configuration in Google Workspace.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Google Workspace Audit Logs
ATT&CK tactics: Defense Evasion (TA0005) Lateral Movement (TA0008)
ATT&CK techniques: Impair Defenses (T1562) Remote Services (T1021)
Detector tags: Google Workspace
Attacker's goals:
Adversaries may modify remote access settings to maintain persistent access and bypass security controls.
Investigative actions:
Verify if the configuration change was authorized. Investigate the source IP address and account involved for malicious activity. Follow further actions performed by the account and Remote Access connections performed.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Suspicious Chrome OS Remote Access policy was modified in Google Workspace Low (parent: Informational)