Difference between revisions of "Datadog SIEM Content Packs for Google Workspace"
Jump to navigation
Jump to search
(16 intermediate revisions by the same user not shown) | |||
Line 1: | Line 1: | ||
− | + | * https://docs.datadoghq.com/security/default_rules/#gsuite __NOTOC__ | |
− | + | === High === | |
* <code>Google Workspace Alert Center</code> | * <code>Google Workspace Alert Center</code> | ||
+ | * <code>[[Google Workspace Tor client detected]]</code> | ||
+ | * <code>Google Workspace user assigned supe [[administrative role]]</code> | ||
+ | * <code>Google Workspace user edited [[account recovery]] information</code> | ||
− | + | === Medium === | |
− | |||
− | |||
− | |||
− | |||
− | |||
* <code>Domain added to Google Workspace allowlisted domains</code> | * <code>Domain added to Google Workspace allowlisted domains</code> | ||
− | |||
* <code>Google Workspace accessed by Google</code> | * <code>Google Workspace accessed by Google</code> | ||
− | |||
* <code>Google Workspace administrator has disabled 2-step verification for organizational unit</code> | * <code>Google Workspace administrator has disabled 2-step verification for organizational unit</code> | ||
+ | === Low === | ||
+ | * <code>Google Workspace admin role created</code> | ||
+ | * <code>Google Workspace administrator initiated a data transfer request</code> | ||
+ | * <code>Google Workspace user assigned administrative role</code> | ||
+ | * <code>Google Workspace user disabled 2-step verification</code> | ||
+ | * <code>Google Workspace user forwarding email out of non Google Workspace domain</code> | ||
+ | * <code>Google Workspace user has unenrolled from Advanced Protection</code> | ||
+ | * <code>Large amount of downloads on [[Google Drive]]</code> | ||
+ | * <code>User attempted login with [[leaked]] password</code> | ||
== See also == | == See also == | ||
+ | * {{dd gsuite}} | ||
+ | * {{Content Packs}} | ||
* {{DD SIEM}} | * {{DD SIEM}} | ||
− | |||
[[Category:Google]] | [[Category:Google]] |
Latest revision as of 11:27, 12 October 2024
High[edit]
Google Workspace Alert Center
Google Workspace Tor client detected
Google Workspace user assigned supe administrative role
Google Workspace user edited account recovery information
Medium[edit]
Domain added to Google Workspace allowlisted domains
Google Workspace accessed by Google
Google Workspace administrator has disabled 2-step verification for organizational unit
Low[edit]
Google Workspace admin role created
Google Workspace administrator initiated a data transfer request
Google Workspace user assigned administrative role
Google Workspace user disabled 2-step verification
Google Workspace user forwarding email out of non Google Workspace domain
Google Workspace user has unenrolled from Advanced Protection
Large amount of downloads on Google Drive
User attempted login with leaked password
See also[edit]
Advertising: