kevmap

Log sources › saas:googleworkspace

saas:googleworkspace

Inverted view: what can be detected if this is the log you have. SaaS

7
channels
6
analytics
6
techniques
6
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
API access without user login DC0002 User Account Authentication AN0957 1
Access via OAuth credentials with unusual scopes or from anomalous IPs DC0002 User Account Authentication AN1427 1
Accessed third-party credential management service DC0002 User Account Authentication AN1156 1
OAuth2 authorization grants / Admin role assignments DC0038 Application Log Content AN1349 1
OAuthTokenGranted, APIRequest DC0007 Web Credential Usage AN0528 1
access_token issued DC0007 Web Credential Usage AN0957 1
login with reused session token and mismatched user agent or IP DC0002 User Account Authentication AN1406 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1199 Trusted Relationshipinitial access21
T1528 Steal Application Access Tokencredential access141
T1539 Steal Web Session Cookiecredential access20
T1550 Use Alternate Authentication Materiallateral movement50
T1550.001 Application Access Tokenlateral movement40
T1552 Unsecured Credentialscredential access134

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2020-5902F5 BIG-IP T1552 Stale
CVE-2023-49103ownCloud ownCloud graphapi T1552 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1552 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1552 Mapped
CVE-2024-38475Apache HTTP Server T1528 Mapped
CVE-2024-53704SonicWall SonicOS T1199 Mapped