Mobile / Device Management
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Source-only rules that filter on applicationName 'mobile' without specifying an eventName attribute here. | N | N |
| DEVICE_ | A mobile or managed device was registered or unregistered from Google Workspace MDM. Elastic uses dataset 'google_workspace.device' for this applicationName. | N | Y |
| DEVICE_ | A managed device was detected as compromised or rooted/jailbroken. | N | Y |
| DEVICE_ | An administrative action was taken on a managed device (e.g. remote wipe, lock). | N | N |
| FAILED_ | Multiple failed attempts to unlock a managed device were detected. | N | Y |
| SUSPICIOUS_ | Suspicious activity was detected on a managed mobile device. | N | Y |
| DEVICE_ | A managed device synced with Google Workspace MDM. | N | N |
| DEVICE_ | A managed device's compliance status changed. | N | N |
any: Mobile / Device Management (any event)
#Description
Source-only rules that filter on applicationName 'mobile' without specifying an eventName attribute here.
References #
DEVICE_REGISTER_UNREGISTER_EVENT: Device Register/Unregister Event
#Description
A mobile or managed device was registered or unregistered from Google Workspace MDM. Elastic uses dataset 'google_workspace.device' for this applicationName.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
google_workspace.device.account_state (GWS) | eq | registered | 2 rules | elastic |
user.email (elastic rule field) | is_not_null | | 2 rules | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1078, T1078.004, T1098, T1098.005T1078, T1078.004, T1098, T1098.005, T1557
References #
DEVICE_COMPROMISED_EVENT: Device Compromised Event
#Description
A managed device was detected as compromised or rooted/jailbroken.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
References #
DEVICE_ACTION_EVENT: Device Action Event
#Description
An administrative action was taken on a managed device (e.g. remote wipe, lock).
References #
FAILED_PASSWORD_ATTEMPTS_EVENT: Failed Password Attempts Event
#Description
Multiple failed attempts to unlock a managed device were detected.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1110
References #
SUSPICIOUS_ACTIVITY_EVENT: Suspicious Activity Event
#Description
Suspicious activity was detected on a managed mobile device.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
References #
DEVICE_SYNC_EVENT: Device Sync Event
#Description
A managed device synced with Google Workspace MDM.