Tag
Google Workspace Admin Role Assigned to a User or Group
2 rules 2 TTPsAdversaries leverage the assignment of administrative roles within Google Workspace to an existing or new user/group, establishing persistence and escalating privileges to gain broad control over the tenant, including bypassing single sign-on.
Account Configured with Never-Expiring Password
2 rules 1 TTPDetects the creation and modification of an account with the 'Don't Expire Password' option enabled, which attackers can abuse to persist in the domain and maintain long-term access.
Spike in Active Directory User Modification Activity
2 rules 1 TTPDetects an increase in modifications to AD user objects, which may indicate unauthorized access, impaired defenses, or persistence establishment.
Azure AD Account Created and Deleted Within a Close Time Frame
2 rules 3 TTPsDetection of Azure Active Directory accounts that are created and deleted within a short timeframe, potentially indicating malicious activity such as privilege escalation or persistence attempts.