User Accounts GoogleWorkspace-user_accounts

9 operations, identified by eventName in the audit log.

eventNameDescription
anySource-only rules that filter on applicationName 'user_accounts' without specifying an eventName attribute here.
2sv_disableA user disabled 2-Step Verification on their account (user self-service action).
2sv_enrollA user enrolled in 2-Step Verification (user self-service action).
password_editA user changed their own account password.
recovery_email_editA user changed their account recovery email address.
recovery_phone_editA user changed their account recovery phone number.
email_forwarding_out_of_domainA user configured automatic email forwarding to an external address.
titanium_enrollA user enrolled in Google's Advanced Protection Program.
titanium_unenrollA user left Google's Advanced Protection Program.

any: User Accounts (any event)

#
Application
GoogleWorkspace-user_accounts

Description

Source-only rules that filter on applicationName 'user_accounts' without specifying an eventName attribute here.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

2sv_disable: 2-Step Verification Disabled

#
Application
GoogleWorkspace-user_accounts

Description

A user disabled 2-Step Verification on their account (user self-service action).

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

2sv_enroll: 2-Step Verification Enrolled

#
Application
GoogleWorkspace-user_accounts

Description

A user enrolled in 2-Step Verification (user self-service action).

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

password_edit: Password Edit

#
Application
GoogleWorkspace-user_accounts

Description

A user changed their own account password.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

recovery_email_edit: Recovery Email Edit

#
Application
GoogleWorkspace-user_accounts

Description

A user changed their account recovery email address.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

recovery_phone_edit: Recovery Phone Edit

#
Application
GoogleWorkspace-user_accounts

Description

A user changed their account recovery phone number.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

email_forwarding_out_of_domain: Email Forwarding Out of Domain

#
Application
GoogleWorkspace-user_accounts

Description

A user configured automatic email forwarding to an external address.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
gcp::service_nameeqlogin.googleapis.com1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma #

References #

titanium_enroll: Advanced Protection Enrolled

#
Application
GoogleWorkspace-user_accounts

Description

A user enrolled in Google's Advanced Protection Program.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #

titanium_unenroll: Advanced Protection Unenrolled

#
Application
GoogleWorkspace-user_accounts

Description

A user left Google's Advanced Protection Program.

Fields #

NameDescription
applicationNameReports API applicationName value identifying the GWS service (e.g. admin, login, drive).
eventNameThe specific action within this application.
actor.emailEmail address of the user or administrator who performed the action.
actor.profileIdUnique Google Workspace profile ID of the actor.
ipAddressIP address of the actor at the time of the event.
parametersArray of event-specific key-value parameters documenting affected resources.

References #