Difference between revisions of "Datadog SIEM Content Packs for Google Workspace"

From wikieduonline
Jump to navigation Jump to search
 
(5 intermediate revisions by the same user not shown)
Line 2: Line 2:
 
=== High ===
 
=== High ===
 
* <code>Google Workspace Alert Center</code>
 
* <code>Google Workspace Alert Center</code>
 
 
* <code>Google Workspace [[Tor]] client detected</code>
 
* <code>Google Workspace [[Tor]] client detected</code>
 
+
* <code>Google Workspace user assigned supe [[administrative role]]</code>
* <code>Google Workspace user assigned super administrative role</code>
+
* <code>Google Workspace user edited [[account recovery]] information</code>
 
 
* <code>Google Workspace user edited account recovery information</code>
 
 
 
  
 
=== Medium ===
 
=== Medium ===
 
* <code>Domain added to Google Workspace allowlisted domains</code>
 
* <code>Domain added to Google Workspace allowlisted domains</code>
 
 
* <code>Google Workspace accessed by Google</code>
 
* <code>Google Workspace accessed by Google</code>
 
 
* <code>Google Workspace administrator has disabled 2-step verification for organizational unit</code>
 
* <code>Google Workspace administrator has disabled 2-step verification for organizational unit</code>
  
Line 20: Line 14:
 
=== Low ===
 
=== Low ===
 
* <code>Google Workspace admin role created</code>
 
* <code>Google Workspace admin role created</code>
 
 
* <code>Google Workspace administrator initiated a data transfer request</code>
 
* <code>Google Workspace administrator initiated a data transfer request</code>
 
 
* <code>Google Workspace user assigned administrative role</code>
 
* <code>Google Workspace user assigned administrative role</code>
 
 
* <code>Google Workspace user disabled 2-step verification</code>
 
* <code>Google Workspace user disabled 2-step verification</code>
 
 
* <code>Google Workspace user forwarding email out of non Google Workspace domain</code>
 
* <code>Google Workspace user forwarding email out of non Google Workspace domain</code>
 
 
* <code>Google Workspace user has unenrolled from Advanced Protection</code>
 
* <code>Google Workspace user has unenrolled from Advanced Protection</code>
 
+
* <code>Large amount of downloads on [[Google Drive]]</code>
* <code>Large amount of downloads on Google Drive</code>
+
* <code>User attempted login with [[leaked]] password</code>
 
 
* <code>User attempted login with leaked password</code>
 
  
 
== See also ==
 
== See also ==
 +
* {{Content Packs}}
 
* {{DD SIEM}}
 
* {{DD SIEM}}
 
* {{Google Workspace}}
 
* {{Google Workspace}}
  
 
[[Category:Google]]
 
[[Category:Google]]

Latest revision as of 12:18, 9 October 2024

High[edit]

Medium[edit]

  • Domain added to Google Workspace allowlisted domains
  • Google Workspace accessed by Google
  • Google Workspace administrator has disabled 2-step verification for organizational unit


Low[edit]

  • Google Workspace admin role created
  • Google Workspace administrator initiated a data transfer request
  • Google Workspace user assigned administrative role
  • Google Workspace user disabled 2-step verification
  • Google Workspace user forwarding email out of non Google Workspace domain
  • Google Workspace user has unenrolled from Advanced Protection
  • Large amount of downloads on Google Drive
  • User attempted login with leaked password

See also[edit]

Advertising: