Large amount of downloads on Google Drive

Set up the gsuite integration.

이 페이지는 아직 한국어로 제공되지 않으며 번역 작업 중입니다. 번역에 관한 질문이나 의견이 있으시면 언제든지 저희에게 연락해 주십시오.

Goal

Detect when an attempt to download a large number of Google Drive files occurs.

Strategy

This rule monitors Google Workspace logs to determine when an anomalous number of Google Drive files have been downloaded by a user. An attacker may try to exfiltrate data by downloading files and other sensitive information from the platform.

To reduce false positives the detection looks at download requests that did not originate from an application.

Triage and response

  1. Check for other signals and logs generated by the impacted user {{@usr.email}}, and look for deviations in the following properties:
    • Application
    • Device
    • Geolocation
    • IP address
  2. Reach out to the user {{@usr.email}} to confirm if they recognize the activity.
  3. If the activity is not legitimate, block the user from signing in and begin your Incident Response process.