Chrome Management GoogleWorkspace-chrome

11 operations, identified by eventName in the audit log.

eventNameDescription
anySource-only rules that filter on applicationName 'chrome' without specifying an eventName attribute here.
badNavigationEventA Chrome browser user navigated to a site blocked by Safe Browsing.
contentTransferEventA content transfer (upload or download) was detected by Chrome Enterprise.
dangerousDownloadEventA Chrome user downloaded a file flagged as dangerous by Safe Browsing.
unscannedFileEventA Chrome user attempted to download a file that could not be scanned for malware.
CHROME_OS_LOGIN_EVENTA user logged in to a Chrome OS device.
CHROME_OS_LOGOUT_EVENTA user logged out of a Chrome OS device.
CHROME_OS_LOGIN_FAILURE_EVENTA login attempt on a Chrome OS device failed.
DLP_EVENTA Chrome Enterprise data loss prevention policy was triggered.
PASSWORD_REUSEA Chrome user reused a corporate password on a non-corporate site.
DEVICE_BOOT_STATE_CHANGEA Chrome OS device changed its boot state (e.g. verified boot status changed).

any: Chrome Management (any event)

#
Application
GoogleWorkspace-chrome

Description

Source-only rules that filter on applicationName 'chrome' without specifying an eventName attribute here.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

badNavigationEvent: Bad Navigation Event

#
Application
GoogleWorkspace-chrome

Description

A Chrome browser user navigated to a site blocked by Safe Browsing.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

contentTransferEvent: Content Transfer Event

#
Application
GoogleWorkspace-chrome

Description

A content transfer (upload or download) was detected by Chrome Enterprise.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

dangerousDownloadEvent: Dangerous Download Event

#
Application
GoogleWorkspace-chrome

Description

A Chrome user downloaded a file flagged as dangerous by Safe Browsing.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

unscannedFileEvent: Unscanned File Event

#
Application
GoogleWorkspace-chrome

Description

A Chrome user attempted to download a file that could not be scanned for malware.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

CHROME_OS_LOGIN_EVENT: Chrome OS Login Event

#
Application
GoogleWorkspace-chrome

Description

A user logged in to a Chrome OS device.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

CHROME_OS_LOGOUT_EVENT: Chrome OS Logout Event

#
Application
GoogleWorkspace-chrome

Description

A user logged out of a Chrome OS device.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

CHROME_OS_LOGIN_FAILURE_EVENT: Chrome OS Login Failure

#
Application
GoogleWorkspace-chrome

Description

A login attempt on a Chrome OS device failed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

DLP_EVENT: DLP Event

#
Application
GoogleWorkspace-chrome

Description

A Chrome Enterprise data loss prevention policy was triggered.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

PASSWORD_REUSE: Password Reuse

#
Application
GoogleWorkspace-chrome

Description

A Chrome user reused a corporate password on a non-corporate site.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

DEVICE_BOOT_STATE_CHANGE: Device Boot State Change

#
Application
GoogleWorkspace-chrome

Description

A Chrome OS device changed its boot state (e.g. verified boot status changed).

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #