logo

Google Workspace Attack Surface

ID: 722a5c65-6bb3-5b6c-9004-06611b7475fc

STIX ID: report--722a5c65-6bb3-5b6c-9004-06611b7475fc

Feed Name: Elastic Security Labs

Date Published: 2023-01-03

Date Updated: 2026-04-27

...
...

This publication surveys Google Workspace as an enterprise attack surface, covering administration and OUs, IAM (including service accounts and SAML/SSO), developer interfaces (Apps Script and REST APIs), and core apps (Gmail, Drive, Docs, Sheets), and explains how threat actors commonly exploit these capabilities (phishing, credential and OAuth/API abuse, email collection, and web-service C2) with ATT&CK references; it also reviews native logging, reporting, and rules to strengthen detection and governance, urging organizations to enforce least privilege, monitor audit logs, and take ownership of GW configuration and visibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.