Google Workspace Integration
Detect account compromise and data theft across your Google environment.
What this integration does
Google Workspace meets agentic SOC
Google Workspace is a common target for phishing, OAuth token abuse, and insider data exfiltration through Drive sharing and export. ManySignal ingests Workspace Admin SDK audit events across Gmail, Drive, Admin, Login, and OAuth audit logs, building behavioural models and detecting threats from initial account compromise through data exfiltration.
Admin SDK audit log ingestion across all Workspace apps
Login event behavioural baselining per user
Drive mass download and external sharing detection
Data collected
- Login audit log events (success, failure, 2SV events)
- Drive audit log (file access, sharing, download events)
- Admin audit log (user management, role changes)
- Gmail audit log (forwarding, delegation, filter events)
- Token audit log (OAuth app authorisations)
Actions supported
- Suspend Google Workspace user
- Sign out all active sessions for a user
- Revoke OAuth application access for a user
- Force password reset on next sign-in
- Remove external sharing from Drive resources
Getting started
Set up in minutes
- 1
Create a GCP service account
- 2
Grant Admin SDK API access
- 3
Configure ManySignal
- 4
Enable the Workspace detection pack
Google Workspace Integration: frequently asked questions
Which Google Workspace editions are supported?
The Admin SDK Reports API is available on Business Standard and above. Business Starter and legacy editions may have limited audit log retention and event types.
Can ManySignal detect Google Drive ransomware simulation?
Yes. ManySignal detects bulk file rename patterns that match known ransomware extensions and large-volume file deletion events, which are common indicators of ransomware or destructive insider activity.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.