Drive GoogleWorkspace-drive

21 operations, identified by eventName in the audit log.

eventNameDescription
anySource-only rules that filter on applicationName 'drive' without specifying an eventName attribute here.
change_acl_editorsThe editor access-control list for a Drive file was changed.
change_document_access_scopeThe access scope of a Drive document was changed (e.g. from private to shared).
change_document_visibilityThe visibility setting of a Drive document was changed.
change_user_accessA user's access to a Drive file was changed.
copyA Drive file was copied.
deleteA Drive file was permanently deleted.
downloadA Drive file was downloaded.
email_as_attachmentA Drive file was sent as an email attachment.
source_copyA Drive file was copied from an external source.
trashA Drive file was moved to trash.
viewA Drive file was viewed.
createA new file or folder was created in Drive.
editA Drive file was edited.
renameA Drive file or folder was renamed.
moveA Drive file or folder was moved to a different location.
uploadA file was uploaded to Drive.
printA Drive file was printed.
request_accessA user requested access to a Drive file they do not have permission to view.
deny_access_requestAn access request to a Drive file was denied.
add_to_folderA Drive file was added to a folder.

any: Drive (any event)

#
Application
GoogleWorkspace-drive

Description

Source-only rules that filter on applicationName 'drive' without specifying an eventName attribute here.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

change_acl_editors: Change ACL Editors

#
Application
GoogleWorkspace-drive

Description

The editor access-control list for a Drive file was changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
about.labels["is_suspicious"]eqtrue1 rulechronicle
target.user.email_addressesregex_match.*@gmail\.com|.*@aol\.com|.*@ymail\.com|.*@ymail\.com|.*@hotmail\.com|.*@outlook\.com|.*@icloud\.com1 rulechronicle

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

change_document_access_scope: Change Document Access Scope

#
Application
GoogleWorkspace-drive

Description

The access scope of a Drive document was changed (e.g. from private to shared).

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
about.labels["is_suspicious"]eqtrue1 rulechronicle
target.user.email_addressesregex_match.*@gmail\.com|.*@aol\.com|.*@ymail\.com|.*@ymail\.com|.*@hotmail\.com|.*@outlook\.com|.*@icloud\.com1 rulechronicle

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

change_document_visibility: Change Document Visibility

#
Application
GoogleWorkspace-drive

Description

The visibility setting of a Drive document was changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
about.labels["is_suspicious"]eqtrue1 rulechronicle
target.user.email_addressesregex_match.*@gmail\.com|.*@aol\.com|.*@ymail\.com|.*@ymail\.com|.*@hotmail\.com|.*@outlook\.com|.*@icloud\.com1 rulechronicle

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

change_user_access: Change User Access

#
Application
GoogleWorkspace-drive

Description

A user's access to a Drive file was changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
about.labels["is_suspicious"]eqtrue1 rulechronicle
target.user.email_addressesregex_match.*@gmail\.com|.*@aol\.com|.*@ymail\.com|.*@ymail\.com|.*@hotmail\.com|.*@outlook\.com|.*@icloud\.com1 rulechronicle

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

copy: Copy

#
Application
GoogleWorkspace-drive

Description

A Drive file was copied.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
target.resource.attribute.labels["visibility"]eqpeople_with_link2 ruleschronicle
target.resource.attribute.labels["visibility"]eqpublic_on_the_web2 ruleschronicle
EventTypeeqauthorize1 ruleelastic
EventTypeeqcopy1 ruleelastic
gws::token_client_idends_withapps.googleusercontent.com1 ruleelastic

Detection Rules #

View all rules referencing this event →

Elastic #

  • Google Workspace Object Copied to External Drive with App Consent source medium: Detects when a user copies a Google spreadsheet, form, document or script from an external drive. Sequence logic has been added to also detect when a user grants a custom Google application permission via OAuth shortly after. An adversary may send a phishing email to the victim with a Drive object link where "copy" is included in the URI, thus copying the object to the victim's drive. If a container-bound script exists within the object, execution will require permission access via OAuth in which the user has to accept.

YARA-L #

References #

delete: Delete

#
Application
GoogleWorkspace-drive

Description

A Drive file was permanently deleted.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

download: Download

#
Application
GoogleWorkspace-drive

Description

A Drive file was downloaded.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
target.resource.attribute.labels["visibility"]eqpeople_with_link2 ruleschronicle
target.resource.attribute.labels["visibility"]eqpublic_on_the_web2 ruleschronicle
about.labels["is_suspicious"]eqtrue1 rulechronicle

Detection Rules #

View all rules referencing this event →

YARA-L #

Show 1 more (4 total)

References #

email_as_attachment: Email as Attachment

#
Application
GoogleWorkspace-drive

Description

A Drive file was sent as an email attachment.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
target.user.email_addressesregex_match.*@gmail\.com|.*@aol\.com|.*@ymail\.com|.*@ymail\.com|.*@hotmail\.com|.*@outlook\.com|.*@icloud\.com1 rulechronicle

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

source_copy: Source Copy

#
Application
GoogleWorkspace-drive

Description

A Drive file was copied from an external source.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

trash: Trash

#
Application
GoogleWorkspace-drive

Description

A Drive file was moved to trash.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

view: View

#
Application
GoogleWorkspace-drive

Description

A Drive file was viewed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
target.resource.attribute.labels["visibility"]eqpeople_with_link2 ruleschronicle
target.resource.attribute.labels["visibility"]eqpublic_on_the_web2 ruleschronicle

Detection Rules #

View all rules referencing this event →

YARA-L #

References #

create: Create

#
Application
GoogleWorkspace-drive

Description

A new file or folder was created in Drive.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

edit: Edit

#
Application
GoogleWorkspace-drive

Description

A Drive file was edited.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

rename: Rename

#
Application
GoogleWorkspace-drive

Description

A Drive file or folder was renamed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

move: Move

#
Application
GoogleWorkspace-drive

Description

A Drive file or folder was moved to a different location.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

upload: Upload

#
Application
GoogleWorkspace-drive

Description

A file was uploaded to Drive.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

print: Print

#
Application
GoogleWorkspace-drive

request_access: Request Access

#
Application
GoogleWorkspace-drive

Description

A user requested access to a Drive file they do not have permission to view.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

deny_access_request: Deny Access Request

#
Application
GoogleWorkspace-drive

Description

An access request to a Drive file was denied.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

add_to_folder: Add to Folder

#
Application
GoogleWorkspace-drive

Description

A Drive file was added to a folder.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #