Analytics BIOC Informational

Data Sharing between GCP and Google Workspace was disabled

An identity has modified data sharing settings between GCP and Google Workspace.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Defense Evasion (TA0005) Impact (TA0040)
ATT&CK techniques: Indicator Removal (T1070) Impair Defenses (T1562) Data Manipulation (T1565) Impair Defenses: Disable or Modify Cloud Logs (T1562.008)
Detector tags: Google Workspace
Attacker's goals:

Adversaries may stop audit log events from being sent to remove evidence of their presence or hinder defenses.

Investigative actions:

Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check whether Google Workspace audit log events were configured to be sent to Google Cloud. Follow further actions done by the account.

Test period:
N/A (single event)
Deduplication:
2 Days
3 variations:
  • Data Sharing between GCP and Google Workspace was disabled by a suspicious identity Low (parent: Informational)
  • Data Sharing between GCP and Google Workspace was disabled by a non Google Workspace administrative user Low (parent: Informational)
  • Data Sharing between GCP and Google Workspace was disabled from an unusual ASN Low (parent: Informational)