For the complete documentation index, see llms.txt. This page is also available as Markdown.

External Sharing was turned on for Google Drive

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Google Workspace Audit Logs

Detection Modules

Identity Threat Module, SaaS Threat Detection

Detector Tags

Google Workspace

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Transfer Data to Cloud Account (T1537)

Severity

Informational

Description

An identity has modified Google Drive sharing settings and allowed external sharing.

Attacker's Goals

Adversaries may exfiltrate data, such as sensitive documents.

Investigative actions

  • Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

  • check the new setting details.

  • Follow further actions done by the account.

Variations

External Sharing was turned on for Google Drive by a non Google Workspace administrative user from an unusual ASN

Synopsis

Field
Value

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Transfer Data to Cloud Account (T1537)

Severity

Low

Description

An identity has modified Google Drive sharing settings and allowed external sharing.

Attacker's Goals

Adversaries may exfiltrate data, such as sensitive documents.

Investigative actions

  • Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

  • check the new setting details.

  • Follow further actions done by the account.

External Sharing was turned on for Google Drive by a non Google Workspace administrative user

Synopsis

Field
Value

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Transfer Data to Cloud Account (T1537)

Severity

Low

Description

An identity has modified Google Drive sharing settings and allowed external sharing.

Attacker's Goals

Adversaries may exfiltrate data, such as sensitive documents.

Investigative actions

  • Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

  • check the new setting details.

  • Follow further actions done by the account.

External Sharing was turned on for Google Drive from an unusual ASN

Synopsis

Field
Value

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Transfer Data to Cloud Account (T1537)

Severity

Low

Description

An identity has modified Google Drive sharing settings and allowed external sharing.

Attacker's Goals

Adversaries may exfiltrate data, such as sensitive documents.

Investigative actions

  • Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

  • check the new setting details.

  • Follow further actions done by the account.

Was this helpful?