Elastic high stable kql
Google Workspace API Access Granted via Domain-Wide Delegation
Detects when a super administrator authorizes domain-wide delegation (DWD) API client access for a Google Cloud service account or OAuth client. DWD lets an application impersonate users and access Workspace APIs across the tenant. Adversaries with admin access may register or authorize a malicious client with broad scopes to maintain API-based persistence and access mail, drive, and directory data without relying on a single user's password alone.
Detection Logic
data_stream.dataset:google_workspace.admin
and event.action:AUTHORIZE_API_CLIENT_ACCESS False Positives
- ⚠ Domain-wide delegation of authority may be granted to service accounts by system administrators. Verify that the configuration change was expected. Exceptions can be added to this rule to filter expected behavior.
Field Validations
Loading…
Comments (0)
Loading comments...