elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.88k stars 481 forks source link

[Meta] Review Elastic Gmail Connector for Email Detection Rules #3324

Open terrancedejesus opened 8 months ago

terrancedejesus commented 8 months ago

Parent Epic (If Applicable)

Meta Summary

This meta is used to track the review of Elastic's Gmail connector. This connector uses the Gmail API to asynchronously request Gmail logs for each user entity in the Google Workspace organization.

At this time, the Google Workspace integration does not ingest Gmail logs as a result of the Reports: Admin API endpoint in Google Workspace not providing them.

Estimated Time to Complete

1 Week: The scope of this is vague and limited intentionally as a result of this being purely explorational.

Potential Blockers

Tasklist

### Meta Tasks
- [ ] Provide Week 1 Update Comment
- [ ] Provide Week 2 Update or Closeout Comment
- [ ] Setup Gmail Connector in Controlled Lab
- [ ] Emulate End User Behavior and Analyze Data Ingested
- [ ] Review Data Model and Schema for Plausible Data Points to Write Detection Rules On
- [ ] Determine Connector Schema Validation in Detection Rules if Necessary

Resources / References

botelastic[bot] commented 6 months ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

botelastic[bot] commented 6 months ago

This has been closed due to inactivity. If you feel this is an error, please re-open and include a justifying comment.