An app was removed from a blocked list in Google Workspace
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
2 Days
Required Data
Google Workspace Audit Logs
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Google Workspace
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Modify Authentication Process (T1556)
Severity
Informational
Description
An identity removed an app from Google Workspace blocked OAuth or third-party apps list.
Attacker's Goals
Malicious OAuth Apps can be used to request elevated permissions or to impersonate another user.
Investigative actions
Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Check if the app that was removed from the trusted apps list looks suspicious.
Follow further actions done by the account.
Variations
Was this helpful?
