Analytics BIOC
Informational
✕
Google Workspace automation was created
Google Workspace automation was created.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Google Workspace Audit Logs
ATT&CK tactics: Execution (TA0002) Persistence (TA0003) Exfiltration (TA0010)
ATT&CK techniques: Command and Scripting Interpreter (T1059) Event Triggered Execution (T1546) Automated Exfiltration (T1020)
Detector tags: Google Workspace
Attacker's goals:
Adversaries may create automations to maintain persistence, execute malicious code, or exfiltrate data automatically.
Investigative actions:
Verify if the automation creation was authorized and expected for this user. Investigate the automation logic to determine if it is malicious. Investigate other suspicious activities performed by the user around the same timeframe.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Google Workspace automation was created for a public document Low (parent: Informational)