Mobile / Device Management GoogleWorkspace-mobile

8 operations, identified by eventName in the audit log.

eventNameDescription
anySource-only rules that filter on applicationName 'mobile' without specifying an eventName attribute here.
DEVICE_REGISTER_UNREGISTER_EVENTA mobile or managed device was registered or unregistered from Google Workspace MDM. Elastic uses dataset 'google_workspace.device' for this applicationName.
DEVICE_COMPROMISED_EVENTA managed device was detected as compromised or rooted/jailbroken.
DEVICE_ACTION_EVENTAn administrative action was taken on a managed device (e.g. remote wipe, lock).
FAILED_PASSWORD_ATTEMPTS_EVENTMultiple failed attempts to unlock a managed device were detected.
SUSPICIOUS_ACTIVITY_EVENTSuspicious activity was detected on a managed mobile device.
DEVICE_SYNC_EVENTA managed device synced with Google Workspace MDM.
DEVICE_COMPLIANCE_CHANGED_EVENTA managed device's compliance status changed.

any: Mobile / Device Management (any event)

#
Application
GoogleWorkspace-mobile

Description

Source-only rules that filter on applicationName 'mobile' without specifying an eventName attribute here.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

DEVICE_REGISTER_UNREGISTER_EVENT: Device Register/Unregister Event

#
Application
GoogleWorkspace-mobile

Description

A mobile or managed device was registered or unregistered from Google Workspace MDM. Elastic uses dataset 'google_workspace.device' for this applicationName.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
EventTypeeqDEVICE_REGISTER_UNREGISTER_EVENT2 ruleselastic
gws::device_account_stateeqREGISTERED2 ruleselastic
user.emailis_not_null2 ruleselastic

Detection Rules #

View all rules referencing this event →

Elastic #

  • Google Workspace User Sign-in from Atypical Device Type source medium: Detects the first time a Google Workspace user is observed authenticating from a device of a given type (e.g., WINDOWS, MAC, ANDROID, IOS, LINUX) within a historical window. Note that "DEVICE_REGISTER_UNREGISTER_EVENT" events do not represent one-time physical device enrollments; the Google Reports API emits a fresh "google_workspace.device.id" on each event, and the same physical device may produce multiple events per day as sessions/sync renewals occur. The rule therefore surfaces a user authenticating from a new device type, not a new physical device. This is still high-fidelity because adversaries who compromise a Workspace identity via AiTM kits or stolen OAuth refresh tokens frequently relay sessions from device types that diverge from the legitimate user's baseline (e.g., a WINDOWS session appearing for a known macOS user, or simultaneous WINDOWS+MAC sessions within minutes), which is the canonical kit fingerprint. Because the underlying token retains access after password rotation, treat unexpected device-type divergence as a compromise indicator and revoke tokens, not just credentials.
  • Google Workspace Device Registration Burst for Single User source medium: Detects bursts of Google Workspace device registration events for the same user, where three or more distinct "google_workspace.device.id" values are emitted in a one-minute window. Although "DEVICE_REGISTER_UNREGISTER_EVENT" fires routinely on session/sync registration and is not a true physical device enrollment, legitimate user activity typically produces fewer than three distinct device IDs in a single minute. A high-cardinality burst is the fingerprint behavior of AiTM phishing-kit relays (Tycoon2FA Google variant, EvilGinx phishlets) and stolen-OAuth-token replay tooling, both of which mint a new session attestation per relay or replay attempt.

References #

DEVICE_COMPROMISED_EVENT: Device Compromised Event

#
Application
GoogleWorkspace-mobile

Description

A managed device was detected as compromised or rooted/jailbroken.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

DEVICE_ACTION_EVENT: Device Action Event

#
Application
GoogleWorkspace-mobile

Description

An administrative action was taken on a managed device (e.g. remote wipe, lock).

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

FAILED_PASSWORD_ATTEMPTS_EVENT: Failed Password Attempts Event

#
Application
GoogleWorkspace-mobile

Description

Multiple failed attempts to unlock a managed device were detected.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

SUSPICIOUS_ACTIVITY_EVENT: Suspicious Activity Event

#
Application
GoogleWorkspace-mobile

Description

Suspicious activity was detected on a managed mobile device.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

DEVICE_SYNC_EVENT: Device Sync Event

#
Application
GoogleWorkspace-mobile

Description

A managed device synced with Google Workspace MDM.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

DEVICE_COMPLIANCE_CHANGED_EVENT: Device Compliance Changed Event

#
Application
GoogleWorkspace-mobile

Description

A managed device's compliance status changed.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #