Calendar

eventNameDescriptionSampleRule
anySource-only rules that filter on applicationName 'calendar' without specifying an eventName attribute here.NN
change_calendar_aclsAccess control settings for a calendar were changed.NY
create_calendarA new calendar was created.YN
delete_calendarA calendar was deleted.NN
create_eventA calendar event was created.NN
delete_eventA calendar event was deleted.NN
add_event_guestA guest was added to a calendar event.NN
remove_event_guestA guest was removed from a calendar event.NN
export_calendarA calendar was exported.NN
add_subscriptionA user subscribed to a calendar.YN
delete_subscriptionA user unsubscribed from a calendar.NN
change_event_guest_responseA guest's response to a calendar event invitation was changed.NN
notification_triggeredA calendar notification was triggered.NN

any: Calendar (any event)

#
ApplicationName
calendar

Description

Source-only rules that filter on applicationName 'calendar' without specifying an eventName attribute here.

References #

change_calendar_acls: Change Calendar ACLs

#
ApplicationName
calendar

Description

Access control settings for a calendar were changed.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

create_calendar: Create Calendar

#
ApplicationName
calendar

Description

A new calendar was created.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-07-21T13:40:53.794Z",
    "uniqueQualifier": "-6782823658469990544",
    "applicationName": "calendar",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/5mkU4egiM5liwfIcNDWXr554axw\"",
  "actor": {
    "email": "suspicious@cloud-response.com",
    "profileId": "102509620547980436027"
  },
  "ownerDomain": "cloud-response.com",
  "ipAddress": "80.114.222.200",
  "events": [
    {
      "type": "calendar_change",
      "name": "create_calendar",
      "parameters": [
        {
          "name": "calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "target_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "user_agent",
          "value": "Mozilla/5.0"
        }
      ]
    }
  ]
}

References #

delete_calendar: Delete Calendar

#
ApplicationName
calendar

Description

A calendar was deleted.

References #

create_event: Create Event

#
ApplicationName
calendar

Description

A calendar event was created.

References #

delete_event: Delete Event

#
ApplicationName
calendar

Description

A calendar event was deleted.

References #

add_event_guest: Add Event Guest

#
ApplicationName
calendar

Description

A guest was added to a calendar event.

References #

remove_event_guest: Remove Event Guest

#
ApplicationName
calendar

Description

A guest was removed from a calendar event.

References #

export_calendar: Export Calendar

#
ApplicationName
calendar

Description

A calendar was exported.

References #

add_subscription: Add Subscription

#
ApplicationName
calendar

Description

A user subscribed to a calendar.

Example Audit Activity #

{
  "kind": "admin#reports#activity",
  "id": {
    "time": "2022-07-21T13:40:54.384Z",
    "uniqueQualifier": "-3423840045468797090",
    "applicationName": "calendar",
    "customerId": "C00mpaiwz"
  },
  "etag": "\"_ZVRqe-BUDYcYeOIPo-gm6Eh1QaGne4ACjHHI6qsr6A/R2REK3zHN6JRbMbXygki_D47fFs\"",
  "actor": {
    "email": "suspicious@cloud-response.com",
    "profileId": "102509620547980436027"
  },
  "ownerDomain": "cloud-response.com",
  "ipAddress": "80.114.222.200",
  "events": [
    {
      "type": "subscription_change",
      "name": "add_subscription",
      "parameters": [
        {
          "name": "subscriber_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "target_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "notification_type",
          "value": "event_reminder"
        },
        {
          "name": "notification_method",
          "value": "alert"
        },
        {
          "name": "user_agent",
          "value": "Mozilla/5.0"
        }
      ]
    },
    {
      "type": "subscription_change",
      "name": "add_subscription",
      "parameters": [
        {
          "name": "subscriber_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "target_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "notification_type",
          "value": "new_event"
        },
        {
          "name": "notification_method",
          "value": "email"
        },
        {
          "name": "user_agent",
          "value": "Mozilla/5.0"
        }
      ]
    },
    {
      "type": "subscription_change",
      "name": "add_subscription",
      "parameters": [
        {
          "name": "subscriber_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "target_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "notification_type",
          "value": "changed_event"
        },
        {
          "name": "notification_method",
          "value": "email"
        },
        {
          "name": "user_agent",
          "value": "Mozilla/5.0"
        }
      ]
    },
    {
      "type": "subscription_change",
      "name": "add_subscription",
      "parameters": [
        {
          "name": "subscriber_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "target_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "notification_type",
          "value": "cancelled_event"
        },
        {
          "name": "notification_method",
          "value": "email"
        },
        {
          "name": "user_agent",
          "value": "Mozilla/5.0"
        }
      ]
    },
    {
      "type": "subscription_change",
      "name": "add_subscription",
      "parameters": [
        {
          "name": "subscriber_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "target_calendar_id",
          "value": "workspace@cloud-response.com"
        },
        {
          "name": "notification_type",
          "value": "reply_received"
        },
        {
          "name": "notification_method",
          "value": "email"
        },
        {
          "name": "user_agent",
          "value": "Mozilla/5.0"
        }
      ]
    }
  ]
}

References #

delete_subscription: Delete Subscription

#
ApplicationName
calendar

Description

A user unsubscribed from a calendar.

References #

change_event_guest_response: Change Event Guest Response

#
ApplicationName
calendar

Description

A guest's response to a calendar event invitation was changed.

References #

notification_triggered: Notification Triggered

#
ApplicationName
calendar

Description

A calendar notification was triggered.

References #