{"id":"22f2fb54-5312-435d-852f-7c74f81684ca","title":"Google Workspace Application Access Level Modified","description":"Detects when an access level is changed for a Google workspace application.\nAn access level is part of BeyondCorp Enterprise which is Google Workspace's way of enforcing Zero Trust model.\nAn adversary would be able to remove access levels to gain easier access to Google workspace resources.\n","author":"Bryan Lim","status":"test","level":"medium","date":"2024-01-12","modified":"","tags":["attack.persistence","attack.privilege-escalation","attack.t1098.003"],"technique_ids":["T1098.003"],"logsource":{"product":"gcp","service":"google_workspace.admin"},"falsepositives":["Legitimate administrative activities changing the access levels for an application"],"references":["https://developers.google.com/admin-sdk/reports/v1/appendix/activity/admin-application-settings","https://support.google.com/a/answer/9261439"],"source_path":"rules/cloud/gcp/gworkspace/admin/gcp_gworkspace_application_access_levels_modified.yml","source_sha256":"5ca3a8bd326306f623ed12d7c6bc9b78bb778f6866ff006794ffa1bfda60a10d","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/gcp/gworkspace/admin/gcp_gworkspace_application_access_levels_modified.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Google Workspace Application Access Level Modified\nid: 22f2fb54-5312-435d-852f-7c74f81684ca\nstatus: test\ndescription: |\n    Detects when an access level is changed for a Google workspace application.\n    An access level is part of BeyondCorp Enterprise which is Google Workspace's way of enforcing Zero Trust model.\n    An adversary would be able to remove access levels to gain easier access to Google workspace resources.\nreferences:\n    - https://developers.google.com/admin-sdk/reports/v1/appendix/activity/admin-application-settings\n    - https://support.google.com/a/answer/9261439\nauthor: Bryan Lim\ndate: 2024-01-12\ntags:\n    - attack.persistence\n    - attack.privilege-escalation\n    - attack.t1098.003\nlogsource:\n    product: gcp\n    service: google_workspace.admin\ndetection:\n    selection:\n        eventService: 'admin.googleapis.com'\n        eventName: 'CHANGE_APPLICATION_SETTING'\n        setting_name|startswith: 'ContextAwareAccess'\n    condition: selection\nfalsepositives:\n    - Legitimate administrative activities changing the access levels for an application\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1098.003","id":"T1098.003","name":"Additional Cloud Roles","page":"techniques/enterprise/T1098.003/"}],"data_path":"data/detection-rules/22f2fb54-5312-435d-852f-7c74f81684ca.json","kind":"sigma"}
