For the complete documentation index, see llms.txt. This page is also available as Markdown.

Massive files deletion in Google Drive

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

Google Workspace Audit Logs

Detection Modules

Identity Threat Module

Detector Tags

Data Detection & Response, Google Workspace

ATT&CK Tactic

Impact (TA0040)

ATT&CK Technique

Data Destruction (T1485)

Severity

Informational

Description

A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped.

Attacker's Goals

An attacker may delete files from a SaaS service to wipe data from the organization.

Investigative actions

  • Investigate the source account and verify if it was compromised or performed an authorized activity.

  • Review the files that were deleted to determine if they contain sensitive or critical data.

  • Monitor the account for any further suspicious actions.

Variations

Massive files deletion in Google Drive with suspicious parameters

Synopsis

Field
Value

ATT&CK Tactic

Impact (TA0040)

ATT&CK Technique

Data Destruction (T1485)

Severity

Low

Description

A suspicious user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped.

Attacker's Goals

An attacker may delete files from a SaaS service to wipe data from the organization.

Investigative actions

  • Investigate the source account and verify if it was compromised or performed an authorized activity.

  • Review the files that were deleted to determine if they contain sensitive or critical data.

  • Monitor the account for any further suspicious actions.

Was this helpful?