Analytics BIOC
Informational
✕
Google Workspace user authentication information changed
Google Workspace authentication information was changed for a user.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Google Workspace Audit Logs
ATT&CK tactics: Credential Access (TA0006) Persistence (TA0003)
ATT&CK techniques: Modify Authentication Process: Multi-Factor Authentication (T1556.006) Account Manipulation (T1098)
Detector tags: Google Workspace
Attacker's goals:
Adversaries may manipulate user authentication information to obtain Persistence or Bypass Multi-Factor Authentication (MFA) controls.
Investigative actions:
Verify if the authentication information change was authorized. Follow further actions done by the user and IP address.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Google Workspace administrative user authentication information changed Low (parent: Informational)
- Google Workspace user authentication information changed by another account Low (parent: Informational)