Analytics
Informational
✕
Massive files deletion in Google Drive
A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped.
- Module:
- Identity Threat Detection (ITDR)
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Google Workspace Audit Logs
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Data Destruction (T1485)
Detector tags: Data Detection & Response Google Workspace
Attacker's goals:
An attacker may delete files from a SaaS service to wipe data from the organization.
Investigative actions:
Investigate the source account and verify if it was compromised or performed an authorized activity. Review the files that were deleted to determine if they contain sensitive or critical data. Monitor the account for any further suspicious actions.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- Massive files deletion in Google Drive with suspicious parameters Low (parent: Informational)