GSuite Workspace Calendar External Sharing Setting Change


Description

A Workspace Admin Changed The Sharing Settings for Primary Calendars

Query · python

from panther_gsuite_helpers import gsuite_activityevent_alert_context


def rule(event):
    if not all(
        [
            (event.get("name", "") == "CHANGE_CALENDAR_SETTING"),
            (event.deep_get("parameters", "SETTING_NAME", default="") == "SHARING_OUTSIDE_DOMAIN"),
        ]
    ):
        return False
    return event.deep_get("parameters", "NEW_VALUE", default="") in [
        "READ_WRITE_ACCESS",
        "READ_ONLY_ACCESS",
        "MANAGE_ACCESS",
    ]


def title(event):
    return (
        f"GSuite workspace setting for default calendar sharing was changed by "
        f"[{event.deep_get('actor', 'email', default='<UNKNOWN_EMAIL>')}] "
        + f"from [{event.deep_get('parameters', 'OLD_VALUE', default='<NO_OLD_SETTING_FOUND>')}] "
        + f"to [{event.deep_get('parameters', 'NEW_VALUE', default='<NO_NEW_SETTING_FOUND>')}]"
    )


def alert_context(event):
    return gsuite_activityevent_alert_context(event)

Analyst notes

Restore the calendar sharing setting to the previous value. If unplanned, use indicator search to identify other activity from this administrator.

Raw source GSuite Workspace Calendar External Sharing Setting Change · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Filename: gsuite_workspace_calendar_external_sharing.py
RuleID: "GSuite.Workspace.CalendarExternalSharingSetting"
DisplayName: "GSuite Workspace Calendar External Sharing Setting Change"
Enabled: true
LogTypes:
  - GSuite.ActivityEvent
Tags:
  - GSuite
Reports:
  MITRE ATT&CK:
    - TA0007:T1087
Severity: Medium
Description: >
  A Workspace Admin Changed The Sharing Settings for Primary Calendars
Reference: https://support.google.com/a/answer/60765?hl=en
Runbook: >
  Restore the calendar sharing setting to the previous value.
  If unplanned, use indicator search to identify other activity from this administrator.
SummaryAttributes:
  - actor:email
Tests:
  - Name: Admin Set Default Calendar SHARING_OUTSIDE_DOMAIN Setting to READ_ONLY_ACCESS
    ExpectedResult: true
    Log:
      {
        "actor":
          {
            "callerType": "USER",
            "email": "example@example.io",
            "profileId": "12345",
          },
        "id":
          {
            "applicationName": "admin",
            "customerId": "D12345",
            "time": "2022-12-11 01:06:26.303000000",
            "uniqueQualifier": "-12345",
          },
        "ipAddress": "12.12.12.12",
        "kind": "admin#reports#activity",
        "name": "CHANGE_CALENDAR_SETTING",
        "parameters":
          {
            "DOMAIN_NAME": "example.io",
            "NEW_VALUE": "READ_ONLY_ACCESS",
            "OLD_VALUE": "DEFAULT",
            "ORG_UNIT_NAME": "Example IO",
            "SETTING_NAME": "SHARING_OUTSIDE_DOMAIN",
          },
        "type": "CALENDAR_SETTINGS",
      }
  - Name: Admin Set Default Calendar SHARING_OUTSIDE_DOMAIN Setting to READ_WRITE_ACCESS
    ExpectedResult: true
    Log:
      {
        "actor":
          {
            "callerType": "USER",
            "email": "example@example.io",
            "profileId": "12345",
          },
        "id":
          {
            "applicationName": "admin",
            "customerId": "D12345",
            "time": "2022-12-11 01:06:26.303000000",
            "uniqueQualifier": "-12345",
          },
        "ipAddress": "12.12.12.12",
        "kind": "admin#reports#activity",
        "name": "CHANGE_CALENDAR_SETTING",
        "parameters":
          {
            "DOMAIN_NAME": "example.io",
            "NEW_VALUE": "READ_WRITE_ACCESS",
            "OLD_VALUE": "READ_ONLY_ACCESS",
            "ORG_UNIT_NAME": "Example IO",
            "SETTING_NAME": "SHARING_OUTSIDE_DOMAIN",
          },
        "type": "CALENDAR_SETTINGS",
      }
  - Name: Admin Set Default Calendar SHARING_OUTSIDE_DOMAIN Setting to MANAGE_ACCESS
    ExpectedResult: true
    Log:
      {
        "actor":
          {
            "callerType": "USER",
            "email": "example@example.io",
            "profileId": "12345",
          },
        "id":
          {
            "applicationName": "admin",
            "customerId": "D12345",
            "time": "2022-12-11 01:06:26.303000000",
            "uniqueQualifier": "-12345",
          },
        "ipAddress": "12.12.12.12",
        "kind": "admin#reports#activity",
        "name": "CHANGE_CALENDAR_SETTING",
        "parameters":
          {
            "DOMAIN_NAME": "example.io",
            "NEW_VALUE": "MANAGE_ACCESS",
            "OLD_VALUE": "READ_WRITE_ACCESS",
            "ORG_UNIT_NAME": "Example IO",
            "SETTING_NAME": "SHARING_OUTSIDE_DOMAIN",
          },
        "type": "CALENDAR_SETTINGS",
      }
  - Name: Non-Default Calendar SHARING_OUTSIDE_DOMAIN event
    ExpectedResult: false
    Log:
      {
        "actor":
          {
            "callerType": "USER",
            "email": "user@example.io",
            "profileId": "111111111111111111111",
          },
        "id":
          {
            "applicationName": "admin",
            "customerId": "D12345",
            "time": "2022-12-12 22:21:40.106000000",
            "uniqueQualifier": "1000000000000000000",
          },
        "kind": "admin#reports#activity",
        "name": "CUSTOMER_TAKEOUT_SUCCEEDED",
        "parameters":
          { "OBFUSCATED_CUSTOMER_TAKEOUT_REQUEST_ID": "00mmmmmmmmmmmmm" },
        "type": "CUSTOMER_TAKEOUT",
      }
  - Name: ListObject Type
    ExpectedResult: false
    Log:
      {
        "actor":
          { "email": "user@example.io", "profileId": "118111111111111111111" },
        "id":
          {
            "applicationName": "drive",
            "customerId": "D12345",
            "time": "2022-12-20 17:27:47.080000000",
            "uniqueQualifier": "-7312729053723258069",
          },
        "ipAddress": "12.12.12.12",
        "kind": "admin#reports#activity",
        "name": "rename",
        "parameters":
          {
            "actor_is_collaborator_account": null,
            "billable": true,
            "doc_id": "1GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG",
            "doc_title": "Document Title- Found Here",
            "doc_type": "presentation",
            "is_encrypted": null,
            "new_value": ["Document Title- Found Here"],
            "old_value": ["Document Title- Old"],
            "owner": "user@example.io",
            "owner_is_shared_drive": null,
            "owner_is_team_drive": null,
            "primary_event": true,
            "visibility": "private",
          },
        "type": "access",
      }


# ------ paired body: gsuite_workspace_calendar_external_sharing.py ------

from panther_gsuite_helpers import gsuite_activityevent_alert_context


def rule(event):
    if not all(
        [
            (event.get("name", "") == "CHANGE_CALENDAR_SETTING"),
            (event.deep_get("parameters", "SETTING_NAME", default="") == "SHARING_OUTSIDE_DOMAIN"),
        ]
    ):
        return False
    return event.deep_get("parameters", "NEW_VALUE", default="") in [
        "READ_WRITE_ACCESS",
        "READ_ONLY_ACCESS",
        "MANAGE_ACCESS",
    ]


def title(event):
    return (
        f"GSuite workspace setting for default calendar sharing was changed by "
        f"[{event.deep_get('actor', 'email', default='<UNKNOWN_EMAIL>')}] "
        + f"from [{event.deep_get('parameters', 'OLD_VALUE', default='<NO_OLD_SETTING_FOUND>')}] "
        + f"to [{event.deep_get('parameters', 'NEW_VALUE', default='<NO_NEW_SETTING_FOUND>')}]"
    )


def alert_context(event):
    return gsuite_activityevent_alert_context(event)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.