Google Workspace automation was created
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Google Workspace Audit Logs
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Google Workspace
ATT&CK Tactic
Execution (TA0002), Persistence (TA0003), Exfiltration (TA0010)
ATT&CK Technique
Command and Scripting Interpreter (T1059), Event Triggered Execution (T1546), Automated Exfiltration (T1020)
Severity
Informational
Description
Google Workspace automation was created.
Attacker's Goals
Adversaries may create automations to maintain persistence, execute malicious code, or exfiltrate data automatically.
Investigative actions
Verify if the automation creation was authorized and expected for this user.
Investigate the automation logic to determine if it is malicious.
Investigate other suspicious activities performed by the user around the same timeframe.
Variations
Was this helpful?
