Analytics Informational

Large volume of files potentially containing credentials accessed in Google Drive

A user accessed a large volume of files potentially containing credentials in Google Drive.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Collection (TA0009) Credential Access (TA0006)
ATT&CK techniques: Data from Cloud Storage (T1530) Unsecured Credentials (T1552)
Detector tags: Google Workspace Data Detection & Response
Attacker's goals:

An attacker may attempt to gain unauthorized access by leveraging valid credentials found in Google Drive.

Investigative actions:

Check for signs of account compromise, such as abnormal login activity or unusual behavior. Verify if the user account that accessed the files is authorized to access them. Review the files accessed and whether it was part of a breach or a legitimate activity. Monitor the account for any further suspicious actions.

Test period:
1 Hour
Deduplication:
1 Day
1 variation:
  • Possible credential files harvesting in Google Drive Low (parent: Informational)