Massive files deletion in Google Drive
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
Google Workspace Audit Logs
Detection Modules
Identity Threat Module
Detector Tags
Data Detection & Response, Google Workspace
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Data Destruction (T1485)
Severity
Informational
Description
A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped.
Attacker's Goals
An attacker may delete files from a SaaS service to wipe data from the organization.
Investigative actions
Investigate the source account and verify if it was compromised or performed an authorized activity.
Review the files that were deleted to determine if they contain sensitive or critical data.
Monitor the account for any further suspicious actions.
Variations
Was this helpful?
