Google Workspace Detection Pack
49 detection rules for Google Workspace — covering Super Admin compromise, Gmail forwarding backdoors, Drive mass download, OAuth consent abuse, and insider data staging. One-click activation.
Pack summary
- Detection rules
- 49
- Critical severity
- 12
- Log sources
- 7
- ATT&CK techniques
- 17
What's included
49 rules across 5 threat categories for Google Workspace threats.
Super Admin login anomalies, 2SV disabling, suspicious login flags, impossible travel.
Drive mass download, external sharing, Gmail forwarding, Takeout export, DLP triggers.
Admin role grants, domain-wide delegation, group policy changes, device policy bypass.
Third-party OAuth app consent with broad scopes, service account delegation.
Audit log export disabling, log sink deletion, compliance configuration changes.
Detection rules (20 of 49 shown)
Showing 20 representative rules. All 49 rules activate with one click.
| Rule name | Severity |
|---|---|
| Google Workspace Super Admin Login from New Location | Critical |
| Google Workspace 2-Step Verification Disabled | Critical |
| Google Workspace Admin Role Granted to User | Critical |
| Google Drive — Mass File Download by Single User | High |
| Google Drive Folder Shared Externally to Personal Email | High |
| Gmail Forwarding Rule Created to External Address | Critical |
| Google Workspace OAuth App Authorized with Drive or Gmail Scope | High |
| Google Workspace Domain-Wide Delegation Granted | Critical |
| Google Workspace Login Suspicious Activity Alert | High |
| Google Workspace User Account Suspended | Medium |
| Google Workspace Audit Log Export Disabled | Critical |
| Google Workspace Takeout Data Export Initiated | High |
| Google Workspace New Device Enrolled for User with Elevated Access | Medium |
| Gmail — Sensitive Data Sent to External Domain | High |
| Google Workspace Vault Matter Created for Departing Employee | Low |
| Google Chat External Sharing Enabled for Organisation | Medium |
| Google Workspace Password Reset Not Initiated by User | High |
| Google Workspace Group Made Public with External Members | High |
| Google Workspace Mobile Device Policy Bypassed | Medium |
| Google Workspace Calendar Shared with External User — Detailed Sharing | Low |
Prerequisites
- Google Workspace Admin SDK Reports API enabled and service account with domain-wide delegation configured
- Service account granted the https://www.googleapis.com/auth/admin.reports.audit.readonly scope
- Drive audit logging enabled at Admin Console level (on by default for Business and Enterprise tiers)
- Gmail audit logging and DLP enabled for email-based detections (requires Business Plus or Enterprise)
Google Workspace Detection Pack: frequently asked questions
What Google Workspace log sources does this detection pack use?
The pack uses Google Workspace Admin Audit, Login Audit, Drive Audit, Gmail Audit, OAuth Token Audit, Google Vault Audit, and Calendar Audit logs. ManySignal connects via the Google Workspace Reports API using a service account with domain-wide delegation and the reports.audit.read scope.
How does ManySignal detect Gmail forwarding rule attacks?
Gmail forwarding rule creation is one of the most common post-compromise persistence techniques. ManySignal monitors Gmail audit logs for auto-forward rule creation events and immediately alerts when a rule routes email to an external address. Rules can be automatically removed via the Gmail API response action.
Can ManySignal detect Google Drive data exfiltration?
Yes. Drive Audit logs capture all file download, external share, and copy events. ManySignal's volume-based anomaly detection triggers when a user's download rate exceeds their normal baseline by a configurable threshold. External sharing events to personal email domains are separately flagged as high-severity regardless of volume.
Does this pack cover Google Workspace Business Starter or only Enterprise tiers?
Most Google Workspace audit logs are available from Business Starter upwards. Advanced features — DLP classification in Gmail, Vault, and Context-Aware Access logs — require Business Plus or Enterprise tier. The pack notes tier requirements per rule in the full rule documentation.
How does the pack handle Google Workspace Super Admin accounts?
Super Admin accounts have no access controls by design in Google Workspace. The pack includes dedicated rules for Super Admin login anomalies (new location, suspicious activity flags), Super Admin-initiated policy changes, and domain-wide delegation grants. Super Admin activity is treated as high-risk by default.
Detect Google Workspace threats before data leaves your tenant
49 detection rules for Gmail, Drive, Admin, and OAuth audit logs — covering account takeover, insider data staging, and forwarding backdoors.