Analytics BIOC Informational

Gmail routing settings changed

Gmail routing settings were modified.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data Staged (T1074) Email Collection (T1114)
Detector tags: Google Workspace
Attacker's goals:

Email Collection.

Investigative actions:

Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new routing settings look suspicious. Investigate the IP address associated with the routing settings. Follow further actions done by the account.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Gmail routing settings changed by a non-administrative Google Workspace identity Low (parent: Informational)