
Summary
The GSuite Drive Visibility Changed rule is designed to monitor changes in visibility settings of Google Drive documents to external users. When a document's accessibility is altered, especially making it externally available, it raises security concerns since sensitive information can inadvertently be exposed. This rule captures various access and ACL (Access Control List) change events to ensure that any transition to public accessibility is identified promptly. The rule inspects logs for specific parameters indicating changes in document visibility, ensuring compliance with organizational policies and security standards. Should a document become publicly accessible, the investigation will determine the appropriateness of such visibility.
Categories
- Cloud
- Infrastructure
Data Sources
- User Account
- File
- Application Log
ATT&CK Techniques
- T1213
Created: 2022-09-02