Elastic low stable kql

Google Workspace User Organizational Unit Changed

Users in Google Workspace are typically assigned a specific organizational unit that grants them permissions to certain services and roles that are inherited from this organizational unit. Adversaries may compromise a valid account and change which organizational account the user belongs to which then could allow them to inherit permissions to applications and resources inaccessible prior to.

View Source

Detection Logic

data_stream.dataset:"google_workspace.admin" and google_workspace.event.type:"USER_SETTINGS" and event.action:"MOVE_USER_TO_ORG_UNIT"

False Positives

  • Google Workspace administrators may change which organizational unit a user belongs to as a result of internal role adjustments.

Field Validations

Loading…

Comments (0)

Loading comments...