Skip to content

new: 9 Google Workspace detection rules for missing coverage#5999

Open
saakovv wants to merge 4 commits into
SigmaHQ:masterfrom
saakovv:Saakov-GWS
Open

new: 9 Google Workspace detection rules for missing coverage#5999
saakovv wants to merge 4 commits into
SigmaHQ:masterfrom
saakovv:Saakov-GWS

Conversation

@saakovv
Copy link
Copy Markdown
Contributor

@saakovv saakovv commented May 9, 2026

Summary of the Pull Request

Add 9 new Google Workspace detection rules covering persistence via account and group manipulation, email collection via routing rules, data exfiltration via Drive sharing and ownership transfer, and security control weakening via password policy and calendar settings changes. These scenarios are not currently covered by the existing SigmaHQ GWS rule set.

Changelog

new: Google Workspace User Account Created
new: Google Workspace Trusted Domain Added
new: Google Workspace Gmail Custom Route Created or Modified
new: Google Workspace External User Added to Group
new: Google Workspace Calendar Sharing Setting Changed
new: Google Workspace Application Added to Domain
new: Google Workspace Password Policy Changed
new: Google Workspace Drive File Shared Externally or Publicly
new: Google Workspace Drive File Ownership Transferred

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • Followed SigmaHQ rule creation conventions

@github-actions github-actions Bot added Rules Review Needed The PR requires review labels May 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant