Large volume of files potentially containing credentials accessed in Google Drive
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
Google Workspace Audit Logs
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Google Workspace, Data Detection & Response
ATT&CK Tactic
Collection (TA0009), Credential Access (TA0006)
ATT&CK Technique
Data from Cloud Storage (T1530), Unsecured Credentials (T1552)
Severity
Informational
Description
A user accessed a large volume of files potentially containing credentials in Google Drive.
Attacker's Goals
An attacker may attempt to gain unauthorized access by leveraging valid credentials found in Google Drive.
Investigative actions
Check for signs of account compromise, such as abnormal login activity or unusual behavior.
Verify if the user account that accessed the files is authorized to access them.
Review the files accessed and whether it was part of a breach or a legitimate activity.
Monitor the account for any further suspicious actions.
Variations
Was this helpful?
