Techniques
Sample rules
Google Workspace User Granted Admin Privileges
- source: sigma
- technicques:
- t1098
Description
Detects when an Google Workspace user is granted admin privileges.
Detection logic
condition: selection
selection:
eventName:
- GRANT_DELEGATED_ADMIN_PRIVILEGES
- GRANT_ADMIN_PRIVILEGE
eventService: admin.googleapis.com