For the complete documentation index, see llms.txt. This page is also available as Markdown.

Google Workspace automation was created

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Google Workspace Audit Logs

Detection Modules

Identity Threat Module, SaaS Threat Detection

Detector Tags

Google Workspace

ATT&CK Tactic

Execution (TA0002), Persistence (TA0003), Exfiltration (TA0010)

ATT&CK Technique

Command and Scripting Interpreter (T1059), Event Triggered Execution (T1546), Automated Exfiltration (T1020)

Severity

Informational

Description

Google Workspace automation was created.

Attacker's Goals

Adversaries may create automations to maintain persistence, execute malicious code, or exfiltrate data automatically.

Investigative actions

  • Verify if the automation creation was authorized and expected for this user.

  • Investigate the automation logic to determine if it is malicious.

  • Investigate other suspicious activities performed by the user around the same timeframe.

Variations

Google Workspace automation was created for a public document

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002), Persistence (TA0003), Exfiltration (TA0010)

ATT&CK Technique

Command and Scripting Interpreter (T1059), Event Triggered Execution (T1546), Automated Exfiltration (T1020)

Severity

Low

Description

Google Workspace automation was created.

  • The document that the automation was created for is publicly shared.

Attacker's Goals

Adversaries may create automations to maintain persistence, execute malicious code, or exfiltrate data automatically.

Investigative actions

  • Verify if the automation creation was authorized and expected for this user.

  • Investigate the automation logic to determine if it is malicious.

  • Investigate other suspicious activities performed by the user around the same timeframe.

Was this helpful?