Difference between revisions of "Datadog SIEM Content Packs for Google Workspace"
Jump to navigation
Jump to search
Line 2: | Line 2: | ||
=== High === | === High === | ||
* <code>Google Workspace Alert Center</code> | * <code>Google Workspace Alert Center</code> | ||
− | |||
* <code>Google Workspace [[Tor]] client detected</code> | * <code>Google Workspace [[Tor]] client detected</code> | ||
− | + | * <code>Google Workspace user assigned supe administrative role</code> | |
− | * <code>Google Workspace user assigned | ||
− | |||
* <code>Google Workspace user edited account recovery information</code> | * <code>Google Workspace user edited account recovery information</code> | ||
Line 12: | Line 9: | ||
=== Medium === | === Medium === | ||
* <code>Domain added to Google Workspace allowlisted domains</code> | * <code>Domain added to Google Workspace allowlisted domains</code> | ||
− | |||
* <code>Google Workspace accessed by Google</code> | * <code>Google Workspace accessed by Google</code> | ||
− | |||
* <code>Google Workspace administrator has disabled 2-step verification for organizational unit</code> | * <code>Google Workspace administrator has disabled 2-step verification for organizational unit</code> | ||
Line 20: | Line 15: | ||
=== Low === | === Low === | ||
* <code>Google Workspace admin role created</code> | * <code>Google Workspace admin role created</code> | ||
− | |||
* <code>Google Workspace administrator initiated a data transfer request</code> | * <code>Google Workspace administrator initiated a data transfer request</code> | ||
− | |||
* <code>Google Workspace user assigned administrative role</code> | * <code>Google Workspace user assigned administrative role</code> | ||
− | |||
* <code>Google Workspace user disabled 2-step verification</code> | * <code>Google Workspace user disabled 2-step verification</code> | ||
− | |||
* <code>Google Workspace user forwarding email out of non Google Workspace domain</code> | * <code>Google Workspace user forwarding email out of non Google Workspace domain</code> | ||
− | |||
* <code>Google Workspace user has unenrolled from Advanced Protection</code> | * <code>Google Workspace user has unenrolled from Advanced Protection</code> | ||
− | |||
* <code>Large amount of downloads on Google Drive</code> | * <code>Large amount of downloads on Google Drive</code> | ||
− | |||
* <code>User attempted login with leaked password</code> | * <code>User attempted login with leaked password</code> | ||
Revision as of 11:00, 9 October 2024
Contents
High
Google Workspace Alert Center
Google Workspace Tor client detected
Google Workspace user assigned supe administrative role
Google Workspace user edited account recovery information
Medium
Domain added to Google Workspace allowlisted domains
Google Workspace accessed by Google
Google Workspace administrator has disabled 2-step verification for organizational unit
Low
Google Workspace admin role created
Google Workspace administrator initiated a data transfer request
Google Workspace user assigned administrative role
Google Workspace user disabled 2-step verification
Google Workspace user forwarding email out of non Google Workspace domain
Google Workspace user has unenrolled from Advanced Protection
Large amount of downloads on Google Drive
User attempted login with leaked password
See also
- Datadog SIEM Content Packs: Cloudtrail, Google Workspace
- Datadog security: Datadog Cloud SIEM, Content Packs, Datadog Cloud SIEM signals
- Google Workspace, Google Workspace API, Admin SDK API, Super admin, Directory API,
users.list
,users.insert
, Admin console:admin.google.com
, Terraform provider: googleworkspace, Google Workspace: administrator roles, Google Drive, Google Vault, Spaces, Jamboard, Datadog SIEM
Advertising: