Analytics BIOC
Informational
✕
Google Workspace third-party application's security settings were changed
An identity changed Google Workspace third-party application's security settings.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Google Workspace Audit Logs
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Domain or Tenant Policy Modification (T1484)
Detector tags: Google Workspace
Attacker's goals:
Malicious apps can be used to access the organization's Google data.
Investigative actions:
Check if the identity intended to perform this action, or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Check if the new settings look suspicious. Follow further actions done by the account.
- Test period:
- N/A (single event)
- Deduplication:
- 2 Days
3 variations:
- Google Workspace third-party application's security settings were changed by a suspicious identity Low (parent: Informational)
- Google Workspace third-party application's security settings were changed from an unusual ASN Low (parent: Informational)
- Google Workspace third-party application's security settings were changed by a non Google Workspace administrative user Informational