Gmail

eventNameDescriptionSampleRule
anySource-only rules that filter on applicationName 'gmail' without specifying an eventName attribute here.NY
deliveryA Gmail message delivery event. The event_info.mail_event_type parameter sub-classifies into receive, send, bounce, and other delivery outcomes.NN

any: Gmail (any event)

#
ApplicationName
gmail

Description

Source-only rules that filter on applicationName 'gmail' without specifying an eventName attribute here.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
parameters.message_info.is_spam (panther rule field)eqtrue3 rulespanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

delivery: Delivery

#
ApplicationName
gmail

Description

A Gmail message delivery event. The event_info.mail_event_type parameter sub-classifies into receive, send, bounce, and other delivery outcomes.

References #