Google Workspace user authentication information changed
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Google Workspace Audit Logs
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Google Workspace
ATT&CK Tactic
Credential Access (TA0006), Persistence (TA0003)
ATT&CK Technique
Modify Authentication Process: Multi-Factor Authentication (T1556.006), Account Manipulation (T1098)
Severity
Informational
Description
Google Workspace authentication information was changed for a user.
Attacker's Goals
Adversaries may manipulate user authentication information to obtain Persistence or Bypass Multi-Factor Authentication (MFA) controls.
Investigative actions
Verify if the authentication information change was authorized.
Follow further actions done by the user and IP address.
Variations
Was this helpful?
