For the complete documentation index, see llms.txt. This page is also available as Markdown.

Google Workspace user authentication information changed

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Google Workspace Audit Logs

Detection Modules

Identity Threat Module, SaaS Threat Detection

Detector Tags

Google Workspace

ATT&CK Tactic

Credential Access (TA0006), Persistence (TA0003)

ATT&CK Technique

Modify Authentication Process: Multi-Factor Authentication (T1556.006), Account Manipulation (T1098)

Severity

Informational

Description

Google Workspace authentication information was changed for a user.

Attacker's Goals

Adversaries may manipulate user authentication information to obtain Persistence or Bypass Multi-Factor Authentication (MFA) controls.

Investigative actions

  • Verify if the authentication information change was authorized.

  • Follow further actions done by the user and IP address.

Variations

Google Workspace administrative user authentication information changed

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Persistence (TA0003)

ATT&CK Technique

Modify Authentication Process: Multi-Factor Authentication (T1556.006), Account Manipulation (T1098)

Severity

Low

Description

Google Workspace authentication information was changed for a user.

Attacker's Goals

Adversaries may manipulate user authentication information to obtain Persistence or Bypass Multi-Factor Authentication (MFA) controls.

Investigative actions

  • Verify if the authentication information change was authorized.

  • Follow further actions done by the user and IP address.

Google Workspace user authentication information changed by another account

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Persistence (TA0003)

ATT&CK Technique

Modify Authentication Process: Multi-Factor Authentication (T1556.006), Account Manipulation (T1098)

Severity

Low

Description

Google Workspace authentication information was changed for a user.

Attacker's Goals

Adversaries may manipulate user authentication information to obtain Persistence or Bypass Multi-Factor Authentication (MFA) controls.

Investigative actions

  • Verify if the authentication information change was authorized.

  • Follow further actions done by the user and IP address.

Was this helpful?