Difference between revisions of "Datadog SIEM Content Packs for Google Workspace"

From wikieduonline
Jump to navigation Jump to search
 
Line 1: Line 1:
* https://docs.datadoghq.com/security/default_rules/#gsuite _NOTOC_
+
* https://docs.datadoghq.com/security/default_rules/#gsuite __NOTOC__
 
=== High ===
 
=== High ===
 
* <code>Google Workspace Alert Center</code>
 
* <code>Google Workspace Alert Center</code>

Latest revision as of 11:27, 12 October 2024

High[edit]

Medium[edit]

  • Domain added to Google Workspace allowlisted domains
  • Google Workspace accessed by Google
  • Google Workspace administrator has disabled 2-step verification for organizational unit

Low[edit]

  • Google Workspace admin role created
  • Google Workspace administrator initiated a data transfer request
  • Google Workspace user assigned administrative role
  • Google Workspace user disabled 2-step verification
  • Google Workspace user forwarding email out of non Google Workspace domain
  • Google Workspace user has unenrolled from Advanced Protection
  • Large amount of downloads on Google Drive
  • User attempted login with leaked password

See also[edit]

Advertising: