Analytics BIOC Informational

Google Workspace user authentication information changed

Google Workspace authentication information was changed for a user.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Credential Access (TA0006) Persistence (TA0003)
ATT&CK techniques: Modify Authentication Process: Multi-Factor Authentication (T1556.006) Account Manipulation (T1098)
Detector tags: Google Workspace
Attacker's goals:

Adversaries may manipulate user authentication information to obtain Persistence or Bypass Multi-Factor Authentication (MFA) controls.

Investigative actions:

Verify if the authentication information change was authorized. Follow further actions done by the user and IP address.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Google Workspace administrative user authentication information changed Low (parent: Informational)
  • Google Workspace user authentication information changed by another account Low (parent: Informational)