Domain added to Google Workspace allowlisted domains
Set up the gsuite integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when a domain is added to Google Workspace’s allowlisted domains.
Strategy
This rule monitors Google Workspace logs to determine when a domain was added to Google Workspace’s allowlisted domains. An attacker may add a trusted domain to reduce the level of security controls to allow for the exfiltration or collection of data.
Triage and response
- Reach out to the user or owner of the service account to determine if this action is legitimate.
- If the action is legitimate, consider including the user in a suppression list. See Best practices for creating detection rules with Datadog Cloud SIEM for more information.
- Otherwise, use the Cloud SIEM - User Investigation dashboard to see if the user:
{{@usr.email}}
has taken other actions. - If the results of the triage indicate that an attacker has taken the action, begin your company’s incident response process and an investigation.