Admin Console GoogleWorkspace-admin

54 operations, identified by eventName in the audit log.

eventNameDescription
anySource-only rules that filter on applicationName 'admin' without specifying an eventName attribute here.
ADD_APPLICATIONAn application was added to the Google Workspace domain.
ADD_GROUP_MEMBERA user was added to a group.
ADD_PRIVILEGEA privilege was added to a role.
ADD_TRUSTED_DOMAINSA domain was added to the trusted domains list.
ALLOW_STRONG_AUTHENTICATIONThe administrator changed the MFA enforcement setting (allow/require strong authentication).
ASSIGN_ROLEAn admin role was assigned to a user or service account.
AUTHORIZE_API_CLIENT_ACCESSAn API client was authorized domain-wide access via OAuth.
CHANGE_APPLICATION_SETTINGA setting for a Google Workspace application was modified.
CHANGE_GMAIL_SETTINGA Gmail routing or mail-flow setting was changed.
CREATE_APPLICATION_SETTINGA new application setting was created.
CREATE_DATA_TRANSFER_REQUESTAn admin initiated a data transfer (Drive file ownership reassignment) to another user.
CREATE_GMAIL_SETTINGA new Gmail routing or mail-flow setting was created.
CREATE_ROLEA custom admin role was created.
CUSTOMER_TAKEOUT_CREATEDAn admin initiated a Takeout export job for organizational data.
DELETE_ROLEAn admin role was permanently deleted.
ENFORCE_STRONG_AUTHENTICATIONThe MFA/2SV enforcement policy was changed for the domain or an organizational unit.
GRANT_ADMIN_PRIVILEGEAdministrator privileges were granted to a user account.
GRANT_DELEGATED_ADMIN_PRIVILEGESDelegated administrator privileges were granted to a user.
MOVE_USER_TO_ORG_UNITA user was moved to a different organizational unit.
REMOVE_APPLICATIONAn application was removed from the Google Workspace domain.
REMOVE_APPLICATION_FROM_WHITELISTAn application was removed from the domain's marketplace allowlist.
REMOVE_PRIVILEGEA privilege was removed from a role.
RENAME_ROLEAn admin role was renamed.
SAML2_SERVICE_PROVIDER_CONFIGA SAML 2.0 service provider configuration was added, modified, or removed.
TOGGLE_OUTBOUND_RELAYOutbound email relay routing was enabled or disabled.
TURN_OFF_2_STEP_VERIFICATION2-Step Verification was disabled for a user or the domain.
UNSUSPEND_USERA suspended user account was reactivated.
UPDATE_ROLEAn existing admin role was modified (e.g. description or privileges changed).
BLOCK_ALL_THIRD_PARTY_API_ACCESSAn admin blocked all third-party application access to Google Workspace APIs.
UNBLOCK_ALL_THIRD_PARTY_API_ACCESSAn admin unblocked third-party application access to Google Workspace APIs.
ADD_TO_TRUSTED_OAUTH2_APPSAn OAuth2 application was added to the trusted apps list.
ADD_TO_BLOCKED_OAUTH2_APPSAn OAuth2 application was blocked from accessing Google Workspace data.
REMOVE_FROM_BLOCKED_OAUTH2_APPSAn OAuth2 application was removed from the blocked apps list.
REMOVE_FROM_TRUSTED_OAUTH2_APPSAn OAuth2 application was removed from the trusted apps list.
CREATE_USERA new user account was created in the Google Workspace domain.
DELETE_USERA user account was deleted from the Google Workspace domain.
SUSPEND_USERA user account was suspended by an administrator.
RENAME_USERA user's primary email address was changed.
CHANGE_PASSWORDAn administrator changed a user's password.
REVOKE_ASPAn administrator revoked an application-specific password (ASP) for a user.
REVOKE_3LO_TOKENAn administrator revoked an OAuth token for a user.
SESSION_CONTROL_SETTINGS_CHANGEWeb session duration or re-authentication settings were changed.
WEAK_PROGRAMMATIC_LOGIN_SETTINGS_CHANGEDSettings controlling less-secure app access (LSA/basic auth) were changed.
CHANGE_SSO_SETTINGSSAML/SSO settings for the domain were changed.
TOGGLE_SSO_ENABLEDSSO (SAML-based single sign-on) was enabled or disabled for the domain.
REVOKE_ADMIN_PRIVILEGEAdministrator privileges were revoked from a user account.
ALLOW_SERVICE_FOR_OAUTH2_ACCESSA Google service was allowed for OAuth2 API access.
DISALLOW_SERVICE_FOR_OAUTH2_ACCESSA Google service was disallowed for OAuth2 API access.
TOGGLE_CAA_ENABLEMENTContext-Aware Access was enabled or disabled for the domain.
CHANGE_GROUP_SETTINGA setting for a Google Group was changed by an administrator.
ADD_APPLICATION_TO_WHITELISTAn application was added to the domain's Google Workspace Marketplace allowlist.
CHANGE_TWO_STEP_VERIFICATION_ENROLLMENT_PERIOD_DURATIONThe enrollment period for 2-Step Verification was changed.
CHANGE_ALLOWED_TWO_STEP_VERIFICATION_METHODSThe allowed methods for 2-Step Verification were changed.

any: Admin Console (any event)

#
Application
GoogleWorkspace-admin

Description

Source-only rules that filter on applicationName 'admin' without specifying an eventName attribute here.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

ADD_APPLICATION: Add Application

#
Application
GoogleWorkspace-admin

Description

An application was added to the Google Workspace domain.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Nameeqadmin1 ruleelastic

Detection Rules #

View all rules referencing this event →

Elastic #

  • Application Added to Google Workspace Domain source medium: Detects when a Google marketplace application is added to the Google Workspace domain. An adversary may add a malicious application to an organization’s Google Workspace domain in order to maintain a presence in their target’s organization and steal data.

YARA-L #

  • Google Workspace Application Added source: Identifies when a Marketplace app is added in a Google Workspace organization. Installing certain apps may increase the organization's risk of data exfiltration/leakage and increase its attack surface.

References #

ADD_GROUP_MEMBER: Add Group Member

#
Application
GoogleWorkspace-admin

Description

A user was added to a group.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

Elastic #

  • External User Added to Google Workspace Group source medium: Detects an external Google Workspace user account being added to an existing group. Adversaries may add external user accounts as a means to intercept shared files or emails with that specific group.

YARA-L #

  • Google Workspace External User Added To Group source: Identifies when an external user account is added to a group in Google Workspace. Security teams can monitor for unexpected user accounts being added to Google Workspace groups to prevent unauthorized access to data.

References #

ADD_PRIVILEGE: Add Privilege

#
Application
GoogleWorkspace-admin

Description

A privilege was added to a role.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

Elastic #

  • Google Workspace Role Modified source medium: Detects when a custom admin role or its permissions are modified. An adversary may modify a custom admin role in order to elevate the permissions of other user accounts and persist in their target’s environment.↳ also matches UPDATE_ROLE: Update Role

References #

ADD_TRUSTED_DOMAINS: Add Trusted Domains

#
Application
GoogleWorkspace-admin

Description

A domain was added to the trusted domains list.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Nameeqadmin1 ruleelastic

Detection Rules #

View all rules referencing this event →

Elastic #

  • Domain Added to Google Workspace Trusted Domains source high: Detects when a domain is added to the list of trusted Google Workspace domains. An adversary may add a trusted domain in order to collect and exfiltrate data from their target’s organization with less restrictive security controls.

YARA-L #

  • Google Workspace New Trusted Domain Added source: Identifies when a domain is added to the list of trusted domains in Google Workspace. An adversary may attempt to manipulate sharing settings for trusted domains to gain unauthorized access to sensitive files and folders within an organization.

References #

ALLOW_STRONG_AUTHENTICATION: Allow Strong Authentication

#
Application
GoogleWorkspace-admin

Description

The administrator changed the MFA enforcement setting (allow/require strong authentication).

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
gcp::service_nameeqadmin.googleapis.com1 rulesigma
gws::admin_new_valueeqfalse1 ruleelastic

Detection Rules #

View all rules referencing this event →

Sigma #

Elastic #

YARA-L #

References #

ASSIGN_ROLE: Assign Role

#
Application
GoogleWorkspace-admin

Description

An admin role was assigned to a user or service account.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
security_result.category_detailseqDELEGATED_ADMIN_SETTINGS1 rulechronicle

Detection Rules #

View all rules referencing this event →

Elastic #

  • Google Workspace Admin Role Assigned to a User source high: Assigning the administrative role to a user will grant them access to the Google Admin console and grant them administrator privileges which allow them to access and manage various resources and applications. An adversary may create a new administrator account for persistence or apply the admin role to an existing user to carry out further intrusion efforts. Users with super-admin privileges can bypass single-sign on if enabled in Google Workspace.

YARA-L #

  • Google Workspace Admin Role Assignment source: Identifies when an administrator role is assigned to a user account in Google Workspace. Security teams can monitor for the malicious or accidental assignment of administrator privileges to prevent unauthorized access to data.

References #

AUTHORIZE_API_CLIENT_ACCESS: Authorize API Client Access

#
Application
GoogleWorkspace-admin

Description

An API client was authorized domain-wide access via OAuth.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Nameeqadmin1 ruleelastic
gcp::service_nameeqadmin.googleapis.com1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma #

Elastic #

  • Google Workspace API Access Granted via Domain-Wide Delegation source medium: Detects when a domain-wide delegation of authority is granted to a service account. Domain-wide delegation can be configured to grant third-party and internal applications to access the data of Google Workspace users. An adversary may configure domain-wide delegation to maintain access to their target’s data.

References #

CHANGE_APPLICATION_SETTING: Change Application Setting

#
Application
GoogleWorkspace-admin

Description

A setting for a Google Workspace application was modified.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeeqCHANGE_APPLICATION_SETTING3 ruleselastic
gws::admin_application_nameeqGoogle Workspace Marketplace2 ruleselastic
security_result.category_detailseqAPPLICATION_SETTINGS2 ruleschronicle
Provider_Nameeqadmin1 ruleelastic
gcp::service_nameeqadmin.googleapis.com1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma #

  • Google Workspace Application Access Level Modified source medium: Detects when an access level is changed for a Google workspace application. An access level is part of BeyondCorp Enterprise which is Google Workspace's way of enforcing Zero Trust model. An adversary would be able to remove access levels to gain easier access to Google workspace resources.

Elastic #

  • Application Removed from Blocklist in Google Workspace source medium: Google Workspace administrators may be aware of malicious applications within the Google marketplace and block these applications for user security purposes. An adversary, with administrative privileges, may remove this application from the explicit block list to allow distribution of the application amongst users. This may also indicate the unauthorized use of an application that had been previously blocked before by a user with admin privileges.
  • Google Workspace Bitlocker Setting Disabled source medium: Google Workspace administrators whom manage Windows devices and have Windows device management enabled may also enable BitLocker drive encryption to mitigate unauthorized data access on lost or stolen computers. Adversaries with valid account access may disable BitLocker to access sensitive data on an endpoint added to Google Workspace device management.
  • Google Workspace Restrictions for Marketplace Modified to Allow Any App source medium: Detects when the Google Marketplace restrictions are changed to allow any application for users in Google Workspace. Malicious APKs created by adversaries may be uploaded to the Google marketplace but not installed on devices managed within Google Workspace. Administrators should set restrictions to not allow any application from the marketplace for security reasons. Adversaries may enable any app to be installed and executed on mobile devices within a Google Workspace environment prior to distributing the malicious APK to the end user.
Show 1 more (4 total)

YARA-L #

References #

CHANGE_GMAIL_SETTING: Change Gmail Setting

#
Application
GoogleWorkspace-admin

Description

A Gmail routing or mail-flow setting was changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

Elastic #

  • Google Workspace Custom Gmail Route Created or Modified source medium: Detects when a custom Gmail route is added or modified in Google Workspace. Adversaries can add a custom e-mail route for outbound mail to route these e-mails to their own inbox of choice for data gathering. This allows adversaries to capture sensitive information from e-mail and potential attachments, such as invoices or payment documents. By default, all email from current Google Workspace users with accounts are routed through a domain's mail server for inbound and outbound mail.↳ also matches CREATE_GMAIL_SETTING: Create Gmail Setting

References #

CREATE_APPLICATION_SETTING: Create Application Setting

#
Application
GoogleWorkspace-admin

Description

A new application setting was created.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Nameeqadmin1 ruleelastic
security_result.category_detailseqAPPLICATION_SETTINGS1 rulechronicle

Detection Rules #

View all rules referencing this event →

Elastic #

YARA-L #

References #

CREATE_DATA_TRANSFER_REQUEST: Create Data Transfer Request

#
Application
GoogleWorkspace-admin

Description

An admin initiated a data transfer (Drive file ownership reassignment) to another user.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
security_result.category_detailseqUSER_SETTINGS1 rulechronicle

Detection Rules #

View all rules referencing this event →

Elastic #

YARA-L #

References #

CREATE_GMAIL_SETTING: Create Gmail Setting

#
Application
GoogleWorkspace-admin

Description

A new Gmail routing or mail-flow setting was created.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

Elastic #

  • Google Workspace Custom Gmail Route Created or Modified source medium: Detects when a custom Gmail route is added or modified in Google Workspace. Adversaries can add a custom e-mail route for outbound mail to route these e-mails to their own inbox of choice for data gathering. This allows adversaries to capture sensitive information from e-mail and potential attachments, such as invoices or payment documents. By default, all email from current Google Workspace users with accounts are routed through a domain's mail server for inbound and outbound mail.↳ also matches CHANGE_GMAIL_SETTING: Change Gmail Setting

References #

CREATE_ROLE: Create Role

#
Application
GoogleWorkspace-admin

Description

A custom admin role was created.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Nameeqadmin1 ruleelastic
security_result.category_detailseqDELEGATED_ADMIN_SETTINGS1 rulechronicle

Detection Rules #

View all rules referencing this event →

Elastic #

  • Google Workspace Custom Admin Role Created source medium: Detects when a custom admin role is created in Google Workspace. An adversary may create a custom admin role in order to elevate the permissions of other user accounts and persist in their target’s environment.

YARA-L #

  • Google Workspace Custom Admin Role Created source: Identifies when a custom administrator role is created in Google Workspace. Security teams can monitor for malicious or accidental configuration of administrator privileges to prevent unauthorized access to data.

References #

CUSTOMER_TAKEOUT_CREATED: Customer Takeout Created

#
Application
GoogleWorkspace-admin

Description

An admin initiated a Takeout export job for organizational data.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

Elastic #

References #

DELETE_ROLE: Delete Role

#
Application
GoogleWorkspace-admin

Description

An admin role was permanently deleted.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Nameeqadmin1 ruleelastic
gcp::service_nameeqadmin.googleapis.com1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma #

Elastic #

  • Google Workspace Admin Role Deletion source medium: Detects when a custom admin role is deleted. An adversary may delete a custom admin role in order to impact the permissions or capabilities of system administrators.

References #

ENFORCE_STRONG_AUTHENTICATION: Enforce Strong Authentication

#
Application
GoogleWorkspace-admin

Description

The MFA/2SV enforcement policy was changed for the domain or an organizational unit.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Nameeqadmin2 ruleselastic
gws::admin_new_valueeqfalse2 ruleselastic
gcp::service_nameeqadmin.googleapis.com1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma #

Elastic #

YARA-L #

References #

GRANT_ADMIN_PRIVILEGE: Grant Admin Privilege

#
Application
GoogleWorkspace-admin

Description

Administrator privileges were granted to a user account.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

Sigma #

Kusto #

References #

GRANT_DELEGATED_ADMIN_PRIVILEGES: Grant Delegated Admin Privileges

#
Application
GoogleWorkspace-admin

Description

Delegated administrator privileges were granted to a user.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

Sigma #

References #

MOVE_USER_TO_ORG_UNIT: Move User to Org Unit

#
Application
GoogleWorkspace-admin

Description

A user was moved to a different organizational unit.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
gws::event_typeeqUSER_SETTINGS1 ruleelastic
security_result.category_detailseqUSER_SETTINGS1 rulechronicle

Detection Rules #

View all rules referencing this event →

Elastic #

  • Google Workspace User Organizational Unit Changed source low: Users in Google Workspace are typically assigned a specific organizational unit that grants them permissions to certain services and roles that are inherited from this organizational unit. Adversaries may compromise a valid account and change which organizational account the user belongs to which then could allow them to inherit permissions to applications and resources inaccessible prior to.

YARA-L #

References #

REMOVE_APPLICATION: Remove Application

#
Application
GoogleWorkspace-admin

Description

An application was removed from the Google Workspace domain.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
gcp::service_nameeqadmin.googleapis.com1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma #

References #

REMOVE_APPLICATION_FROM_WHITELIST: Remove Application from Allowlist

#
Application
GoogleWorkspace-admin

Description

An application was removed from the domain's marketplace allowlist.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
gcp::service_nameeqadmin.googleapis.com1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma #

References #

REMOVE_PRIVILEGE: Remove Privilege

#
Application
GoogleWorkspace-admin

Description

A privilege was removed from a role.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

Sigma #

References #

RENAME_ROLE: Rename Role

#
Application
GoogleWorkspace-admin

Description

An admin role was renamed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
gcp::service_nameeqadmin.googleapis.com1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma #

References #

SAML2_SERVICE_PROVIDER_CONFIG: SAML2 Service Provider Config

#
Application
GoogleWorkspace-admin

Description

A SAML 2.0 service provider configuration was added, modified, or removed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

TOGGLE_OUTBOUND_RELAY: Toggle Outbound Relay

#
Application
GoogleWorkspace-admin

Description

Outbound email relay routing was enabled or disabled.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

TURN_OFF_2_STEP_VERIFICATION: Turn Off 2-Step Verification

#
Application
GoogleWorkspace-admin

Description

2-Step Verification was disabled for a user or the domain.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

Kusto #

References #

UNSUSPEND_USER: Unsuspend User

#
Application
GoogleWorkspace-admin

Description

A suspended user account was reactivated.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
gws::event_typeeqUSER_SETTINGS1 ruleelastic

Detection Rules #

View all rules referencing this event →

Elastic #

  • Google Workspace Suspended User Account Renewed source low: Detects when a previously suspended user's account is renewed in Google Workspace. An adversary may renew a suspended user account to maintain access to the Google Workspace organization with a valid account.

YARA-L #

References #

UPDATE_ROLE: Update Role

#
Application
GoogleWorkspace-admin

Description

An existing admin role was modified (e.g. description or privileges changed).

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

Sigma #

Elastic #

References #

BLOCK_ALL_THIRD_PARTY_API_ACCESS: Block All Third-Party API Access

#
Application
GoogleWorkspace-admin

Description

An admin blocked all third-party application access to Google Workspace APIs.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

UNBLOCK_ALL_THIRD_PARTY_API_ACCESS: Unblock All Third-Party API Access

#
Application
GoogleWorkspace-admin

Description

An admin unblocked third-party application access to Google Workspace APIs.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

ADD_TO_TRUSTED_OAUTH2_APPS: Add to Trusted OAuth2 Apps

#
Application
GoogleWorkspace-admin

Description

An OAuth2 application was added to the trusted apps list.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

ADD_TO_BLOCKED_OAUTH2_APPS: Add to Blocked OAuth2 Apps

#
Application
GoogleWorkspace-admin

Description

An OAuth2 application was blocked from accessing Google Workspace data.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

REMOVE_FROM_BLOCKED_OAUTH2_APPS: Remove from Blocked OAuth2 Apps

#
Application
GoogleWorkspace-admin

Description

An OAuth2 application was removed from the blocked apps list.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

REMOVE_FROM_TRUSTED_OAUTH2_APPS: Remove from Trusted OAuth2 Apps

#
Application
GoogleWorkspace-admin

Description

An OAuth2 application was removed from the trusted apps list.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

CREATE_USER: Create User

#
Application
GoogleWorkspace-admin

Description

A new user account was created in the Google Workspace domain.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

DELETE_USER: Delete User

#
Application
GoogleWorkspace-admin

Description

A user account was deleted from the Google Workspace domain.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

SUSPEND_USER: Suspend User

#
Application
GoogleWorkspace-admin

Description

A user account was suspended by an administrator.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

RENAME_USER: Rename User

#
Application
GoogleWorkspace-admin

Description

A user's primary email address was changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

CHANGE_PASSWORD: Change Password

#
Application
GoogleWorkspace-admin

Description

An administrator changed a user's password.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

REVOKE_ASP: Revoke Application-Specific Password

#
Application
GoogleWorkspace-admin

Description

An administrator revoked an application-specific password (ASP) for a user.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

REVOKE_3LO_TOKEN: Revoke OAuth Token

#
Application
GoogleWorkspace-admin

Description

An administrator revoked an OAuth token for a user.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

SESSION_CONTROL_SETTINGS_CHANGE: Session Control Settings Change

#
Application
GoogleWorkspace-admin

Description

Web session duration or re-authentication settings were changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

WEAK_PROGRAMMATIC_LOGIN_SETTINGS_CHANGED: Weak Programmatic Login Settings Changed

#
Application
GoogleWorkspace-admin

Description

Settings controlling less-secure app access (LSA/basic auth) were changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

CHANGE_SSO_SETTINGS: Change SSO Settings

#
Application
GoogleWorkspace-admin

Description

SAML/SSO settings for the domain were changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

TOGGLE_SSO_ENABLED: Toggle SSO Enabled

#
Application
GoogleWorkspace-admin

Description

SSO (SAML-based single sign-on) was enabled or disabled for the domain.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

REVOKE_ADMIN_PRIVILEGE: Revoke Admin Privilege

#
Application
GoogleWorkspace-admin

Description

Administrator privileges were revoked from a user account.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

ALLOW_SERVICE_FOR_OAUTH2_ACCESS: Allow Service for OAuth2 Access

#
Application
GoogleWorkspace-admin

Description

A Google service was allowed for OAuth2 API access.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

DISALLOW_SERVICE_FOR_OAUTH2_ACCESS: Disallow Service for OAuth2 Access

#
Application
GoogleWorkspace-admin

Description

A Google service was disallowed for OAuth2 API access.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

TOGGLE_CAA_ENABLEMENT: Toggle Context-Aware Access Enablement

#
Application
GoogleWorkspace-admin

Description

Context-Aware Access was enabled or disabled for the domain.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

CHANGE_GROUP_SETTING: Change Group Setting

#
Application
GoogleWorkspace-admin

Description

A setting for a Google Group was changed by an administrator.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

ADD_APPLICATION_TO_WHITELIST: Add Application to Allowlist

#
Application
GoogleWorkspace-admin

Description

An application was added to the domain's Google Workspace Marketplace allowlist.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

CHANGE_TWO_STEP_VERIFICATION_ENROLLMENT_PERIOD_DURATION: Change 2SV Enrollment Period Duration

#
Application
GoogleWorkspace-admin

Description

The enrollment period for 2-Step Verification was changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

CHANGE_ALLOWED_TWO_STEP_VERIFICATION_METHODS: Change Allowed 2SV Methods

#
Application
GoogleWorkspace-admin

Description

The allowed methods for 2-Step Verification were changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #