heroui logo

Google Workspace Many Docs Downloaded

Panther Rules

View Source
Summary
The Google Workspace Many Docs Downloaded rule is designed to monitor and detect unusual behavior within Google Drive, specifically focusing on the downloading of documents. The rule triggers if a user downloads more than 20 documents within a 5-minute period, indicating a potential security risk, such as data exfiltration or misuse of access privileges. It utilizes logs from G Suite Activity Events, specifically monitoring for 'download' actions while ignoring 'view' actions. The rule leverages a threshold and deduplication period to manage alerts efficiently, and its severity level is set to medium. This behavior could be an indicator of compromised accounts or insider threats, allowing organizations to respond more effectively to potential data breaches.
Categories
  • Cloud
  • Web
  • Identity Management
Data Sources
  • User Account
  • Cloud Service
  • Application Log
ATT&CK Techniques
  • T1567
Created: 2025-04-05