Analytics BIOC Informational

Security object deletion in Google Workspace Admin Console

A security object was deleted in Google Workspace Admin Console.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Google Workspace Audit Logs
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
Detector tags: Google Workspace
Attacker's goals:

Adversaries may modify or disable security rules to avoid detection of their activities.

Investigative actions:

Investigate the security object name deleted and whether it was intended. Check if the user was recently granted new elevated permissions that allowed them to delete security rules. Follow other administrative or suspicious actions performed by this user around the same time.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Security object deletion in Google Workspace Admin Console for the first time Low (parent: Informational)