Log sources › saas:googleworkspace
saas:googleworkspace
Inverted view: what can be detected if this is the log you have. SaaS
7
channels
6
analytics
6
techniques
6
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
API access without user login |
DC0002 User Account Authentication | AN0957 | 1 |
Access via OAuth credentials with unusual scopes or from anomalous IPs |
DC0002 User Account Authentication | AN1427 | 1 |
Accessed third-party credential management service |
DC0002 User Account Authentication | AN1156 | 1 |
OAuth2 authorization grants / Admin role assignments |
DC0038 Application Log Content | AN1349 | 1 |
OAuthTokenGranted, APIRequest |
DC0007 Web Credential Usage | AN0528 | 1 |
access_token issued |
DC0007 Web Credential Usage | AN0957 | 1 |
login with reused session token and mismatched user agent or IP |
DC0002 User Account Authentication | AN1406 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1199 Trusted Relationship | initial access | 2 | 1 |
| T1528 Steal Application Access Token | credential access | 14 | 1 |
| T1539 Steal Web Session Cookie | credential access | 2 | 0 |
| T1550 Use Alternate Authentication Material | lateral movement | 5 | 0 |
| T1550.001 Application Access Token | lateral movement | 4 | 0 |
| T1552 Unsecured Credentials | credential access | 13 | 4 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2020-5902 | F5 BIG-IP | T1552 | Stale |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1552 | Mapped |
| CVE-2024-20439 | Cisco Smart Licensing Utility | T1552 | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | T1552 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1528 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1199 | Mapped |