Analytics BIOC Informational

Chrome OS Remote Access policy was modified in Google Workspace

A user modified Chrome OS Remote Access configuration in Google Workspace.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Defense Evasion (TA0005) Lateral Movement (TA0008)
ATT&CK techniques: Impair Defenses (T1562) Remote Services (T1021)
Detector tags: Google Workspace
Attacker's goals:

Adversaries may modify remote access settings to maintain persistent access and bypass security controls.

Investigative actions:

Verify if the configuration change was authorized. Investigate the source IP address and account involved for malicious activity. Follow further actions performed by the account and Remote Access connections performed.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Suspicious Chrome OS Remote Access policy was modified in Google Workspace Low (parent: Informational)