Difference between revisions of "Datadog SIEM Content Packs for Google Workspace"
Jump to navigation
Jump to search
(8 intermediate revisions by the same user not shown) | |||
Line 1: | Line 1: | ||
− | + | * https://docs.datadoghq.com/security/default_rules/#gsuite __NOTOC__ | |
=== High === | === High === | ||
* <code>Google Workspace Alert Center</code> | * <code>Google Workspace Alert Center</code> | ||
− | * <code>Google Workspace | + | * <code>[[Google Workspace Tor client detected]]</code> |
− | * <code>Google Workspace user assigned supe administrative role</code> | + | * <code>Google Workspace user assigned supe [[administrative role]]</code> |
− | * <code>Google Workspace user edited account recovery information</code> | + | * <code>Google Workspace user edited [[account recovery]] information</code> |
− | |||
=== Medium === | === Medium === | ||
Line 11: | Line 10: | ||
* <code>Google Workspace accessed by Google</code> | * <code>Google Workspace accessed by Google</code> | ||
* <code>Google Workspace administrator has disabled 2-step verification for organizational unit</code> | * <code>Google Workspace administrator has disabled 2-step verification for organizational unit</code> | ||
− | |||
=== Low === | === Low === | ||
Line 21: | Line 19: | ||
* <code>Google Workspace user has unenrolled from Advanced Protection</code> | * <code>Google Workspace user has unenrolled from Advanced Protection</code> | ||
* <code>Large amount of downloads on [[Google Drive]]</code> | * <code>Large amount of downloads on [[Google Drive]]</code> | ||
− | * <code>User attempted login with leaked password</code> | + | * <code>User attempted login with [[leaked]] password</code> |
== See also == | == See also == | ||
+ | * {{dd gsuite}} | ||
* {{Content Packs}} | * {{Content Packs}} | ||
* {{DD SIEM}} | * {{DD SIEM}} | ||
− | |||
[[Category:Google]] | [[Category:Google]] |
Latest revision as of 11:27, 12 October 2024
High[edit]
Google Workspace Alert Center
Google Workspace Tor client detected
Google Workspace user assigned supe administrative role
Google Workspace user edited account recovery information
Medium[edit]
Domain added to Google Workspace allowlisted domains
Google Workspace accessed by Google
Google Workspace administrator has disabled 2-step verification for organizational unit
Low[edit]
Google Workspace admin role created
Google Workspace administrator initiated a data transfer request
Google Workspace user assigned administrative role
Google Workspace user disabled 2-step verification
Google Workspace user forwarding email out of non Google Workspace domain
Google Workspace user has unenrolled from Advanced Protection
Large amount of downloads on Google Drive
User attempted login with leaked password
See also[edit]
Advertising: