Alerts related to data source "Google Workspace Audit Logs".
A domain was added to the trusted domains list
A GCP service account was delegated domain-wide authority in Google Workspace
A Google Workspace identity created, assigned or modified a role
A Google Workspace identity performed an unusual admin console activity
A Google Workspace identity used the security investigation tool
A Google Workspace Role privilege was deleted
A Google Workspace service was configured as unrestricted
A Google Workspace user was added to a group
A Google Workspace user was removed from a group
A mail forwarding rule was configured in Google Workspace
A third-party application was authorized to access the Google Workspace APIs
A third-party application's access to the Google Workspace domain's resources was revoked
Admin privileges were granted to a Google Workspace user
An app was added to Google Marketplace
An app was added to the Google Workspace trusted OAuth apps list
An app was removed from a blocked list in Google Workspace
Chrome Extension Installed By User
Chrome OS Remote Access policy was modified in Google Workspace
Data Sharing between GCP and Google Workspace was disabled
External SaaS file-sharing activity
External Sharing was turned on for Google Drive
Gmail delegation was turned on for the organization
Gmail routing settings changed
Google Marketplace restrictions were modified
Google Workspace automation was created
Google Workspace organizational unit was modified
Google Workspace third-party application's security settings were changed
Google Workspace user authentication information changed
Large volume of files potentially containing credentials accessed in Google Drive
Massive file downloads from SaaS service
Massive files deletion in Google Drive
Massive upload to SaaS service
MFA Disabled for Google Workspace
MFA was disabled for a Google Workspace user
Potential Phishing has been detected
SaaS suspicious external domain user activity
Security object deletion in Google Workspace Admin Console
Suspicious SaaS API call from a Tor exit node
Suspicious theme and sentiment in email
User accessed SaaS resource via anonymous link
Was this helpful?