Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[New Rule] Multiple successive Google Workspace groups joined or requested to join in short succession #4129

Open
brokensound77 opened this issue Oct 2, 2024 · 0 comments
Assignees
Labels
Rule: New Proposal for new rule Team: TRADE

Comments

@brokensound77
Copy link
Contributor

Description

Identifies multiple successive Google Workspace groups joined or requested to join in short succession, which could indicate attempts to Discover, Collection, or Exfiltration.

Target Ruleset

google_workspace

Target Rule Type

ES|QL

Tested ECS Version

No response

Query

from logs-google_workspace*
| mv_expand event.type
| where event.type == "group" and to_lower(event.action) in ("join", "request_to_join")
| stats total_requests = count(*) by source.user.name
| where total_requests > 5
| sort total_requests desc

This could also be a threshold rule

New fields required in ECS/data sources for this rule?

No response

Related issues or PRs

No response

References

No response

Redacted Example Data

No response

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Rule: New Proposal for new rule Team: TRADE
Projects
None yet
Development

No branches or pull requests

1 participant