logo

Google Workspace Attack Surface

ID: f9ae0ad8-1ea1-58ea-a4a2-36fb9e6c1952

STIX ID: report--f9ae0ad8-1ea1-58ea-a4a2-36fb9e6c1952

Feed Name: Elastic Security Labs

Date Published: 2023-01-03

Date Updated: 2026-04-27

...
...

This document provides a step-by-step guide to build a Google Workspace threat detection lab with Elastic, including GCP/GW configuration (Admin SDK, OAuth consent, service accounts with domain-wide delegation), deploying Elastic Cloud and Fleet, installing the Google Workspace integration, validating log ingestion, and enabling prebuilt detection rules. It also demonstrates crafting a custom detection rule to identify suspicious Gmail routing/forwarding changes, mapping to MITRE ATT&CK techniques, and offers practical queries and workflows to operationalize detections; it does not report on a specific incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.