Data Sharing between GCP and Google Workspace was disabled
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
2 Days
Required Data
Google Workspace Audit Logs
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Google Workspace
ATT&CK Tactic
Defense Evasion (TA0005), Impact (TA0040)
ATT&CK Technique
Indicator Removal (T1070), Impair Defenses (T1562), Data Manipulation (T1565), Impair Defenses: Disable or Modify Cloud Logs (T1562.008)
Severity
Informational
Description
An identity has modified data sharing settings between GCP and Google Workspace.
Attacker's Goals
Adversaries may stop audit log events from being sent to remove evidence of their presence or hinder defenses.
Investigative actions
Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Check whether Google Workspace audit log events were configured to be sent to Google Cloud.
Follow further actions done by the account.
Variations
Was this helpful?
