M ManySignal
Detection Pack Google Workspace

Google Workspace Detection Pack

49 detection rules for Google Workspace — covering Super Admin compromise, Gmail forwarding backdoors, Drive mass download, OAuth consent abuse, and insider data staging. One-click activation.

Pack summary

Detection rules
49
Critical severity
12
Log sources
7
ATT&CK techniques
17

What's included

49 rules across 5 threat categories for Google Workspace threats.

Account Takeover 14 rules

Super Admin login anomalies, 2SV disabling, suspicious login flags, impossible travel.

Data Exfiltration 16 rules

Drive mass download, external sharing, Gmail forwarding, Takeout export, DLP triggers.

Privilege Abuse 8 rules

Admin role grants, domain-wide delegation, group policy changes, device policy bypass.

OAuth & App Threats 6 rules

Third-party OAuth app consent with broad scopes, service account delegation.

Audit & Configuration 5 rules

Audit log export disabling, log sink deletion, compliance configuration changes.

Detection rules (20 of 49 shown)

Showing 20 representative rules. All 49 rules activate with one click.

Rule name Severity
Google Workspace Super Admin Login from New Location Critical
Google Workspace 2-Step Verification Disabled Critical
Google Workspace Admin Role Granted to User Critical
Google Drive — Mass File Download by Single User High
Google Drive Folder Shared Externally to Personal Email High
Gmail Forwarding Rule Created to External Address Critical
Google Workspace OAuth App Authorized with Drive or Gmail Scope High
Google Workspace Domain-Wide Delegation Granted Critical
Google Workspace Login Suspicious Activity Alert High
Google Workspace User Account Suspended Medium
Google Workspace Audit Log Export Disabled Critical
Google Workspace Takeout Data Export Initiated High
Google Workspace New Device Enrolled for User with Elevated Access Medium
Gmail — Sensitive Data Sent to External Domain High
Google Workspace Vault Matter Created for Departing Employee Low
Google Chat External Sharing Enabled for Organisation Medium
Google Workspace Password Reset Not Initiated by User High
Google Workspace Group Made Public with External Members High
Google Workspace Mobile Device Policy Bypassed Medium
Google Workspace Calendar Shared with External User — Detailed Sharing Low

Prerequisites

  • Google Workspace Admin SDK Reports API enabled and service account with domain-wide delegation configured
  • Service account granted the https://www.googleapis.com/auth/admin.reports.audit.readonly scope
  • Drive audit logging enabled at Admin Console level (on by default for Business and Enterprise tiers)
  • Gmail audit logging and DLP enabled for email-based detections (requires Business Plus or Enterprise)

Google Workspace Detection Pack: frequently asked questions

What Google Workspace log sources does this detection pack use?

The pack uses Google Workspace Admin Audit, Login Audit, Drive Audit, Gmail Audit, OAuth Token Audit, Google Vault Audit, and Calendar Audit logs. ManySignal connects via the Google Workspace Reports API using a service account with domain-wide delegation and the reports.audit.read scope.

How does ManySignal detect Gmail forwarding rule attacks?

Gmail forwarding rule creation is one of the most common post-compromise persistence techniques. ManySignal monitors Gmail audit logs for auto-forward rule creation events and immediately alerts when a rule routes email to an external address. Rules can be automatically removed via the Gmail API response action.

Can ManySignal detect Google Drive data exfiltration?

Yes. Drive Audit logs capture all file download, external share, and copy events. ManySignal's volume-based anomaly detection triggers when a user's download rate exceeds their normal baseline by a configurable threshold. External sharing events to personal email domains are separately flagged as high-severity regardless of volume.

Does this pack cover Google Workspace Business Starter or only Enterprise tiers?

Most Google Workspace audit logs are available from Business Starter upwards. Advanced features — DLP classification in Gmail, Vault, and Context-Aware Access logs — require Business Plus or Enterprise tier. The pack notes tier requirements per rule in the full rule documentation.

How does the pack handle Google Workspace Super Admin accounts?

Super Admin accounts have no access controls by design in Google Workspace. The pack includes dedicated rules for Super Admin login anomalies (new location, suspicious activity flags), Super Admin-initiated policy changes, and domain-wide delegation grants. Super Admin activity is treated as high-risk by default.

Detect Google Workspace threats before data leaves your tenant

49 detection rules for Gmail, Drive, Admin, and OAuth audit logs — covering account takeover, insider data staging, and forwarding backdoors.