Techniques
Sample rules
Google Workspace Admin Role Deletion
- source: elastic
- technicques:
- T1531
Description
Detects when a custom admin role is deleted. An adversary may delete a custom admin role in order to impact the permissions or capabilities of system administrators.
Detection logic
event.dataset:google_workspace.admin and event.provider:admin and event.category:iam and event.action:DELETE_ROLE