elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Rule Tuning] External User Added to Google Workspace Group #4128

Open brokensound77 opened 6 days ago

brokensound77 commented 6 days ago

Link to Rule

https://github.com/elastic/detection-rules/blob/51859e57f3e55b0478056c3be6ee27ea9154a70a/rules/integrations/google_workspace/initial_access_external_user_added_to_google_workspace_group.toml#L87

Rule Tuning Type

False Negatives - Enhancing detection of true threats that were previously missed.

Description

Tune event.action to include GROUP_MEMBER_BULK_UPLOAD in addition to the existing ADD_GROUP_MEMBER

Example Data

No response