A Google Workspace identity performed an unusual admin console activity
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
2 Days
Required Data
Google Workspace Audit Logs
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Google Workspace
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
A Google Workspace identity performed an admin console activity for the first time.
Attacker's Goals
To do.
Investigative actions
Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Check if the changes that were made look suspicious.
Follow further actions done by the account.
Variations
PreviousA Google Workspace identity created, assigned or modified a role
NextA Google Workspace identity used the security investigation tool
Was this helpful?
