GSuite Workspace Gmail Pre-Delivery Message Scanning Disabled


Description

A Workspace Admin Has Disabled Pre-Delivery Scanning For Gmail.

Query · python

from panther_gsuite_helpers import gsuite_activityevent_alert_context


def rule(event):
    # the shape of the items in parameters can change a bit ( like NEW_VALUE can be an array )
    #  when the applicationName is something other than admin
    if event.deep_get("id", "applicationName", default="").lower() != "admin":
        return False
    if all(
        [
            (event.get("name", "") == "CHANGE_APPLICATION_SETTING"),
            (event.deep_get("parameters", "APPLICATION_NAME", default="").lower() == "gmail"),
            (event.deep_get("parameters", "NEW_VALUE", default="").lower() == "true"),
            (
                event.deep_get("parameters", "SETTING_NAME", default="")
                == "DelayedDeliverySettingsProto disable_delayed_delivery_for_suspicious_email"
            ),
        ]
    ):
        return True
    return False


def title(event):
    return (
        f"GSuite Gmail Enhanced Pre-Delivery Scanning was disabled "
        f"for [{event.deep_get('parameters', 'ORG_UNIT_NAME', default='<NO_ORG_UNIT_NAME>')}] "
        f"by [{event.deep_get('actor', 'email', default='<UNKNOWN_EMAIL>')}]"
    )


def alert_context(event):
    return gsuite_activityevent_alert_context(event)

Analyst notes

Pre-delivery scanning is a feature in Gmail that subjects suspicious emails to additional automated scrutiny by Google.

If this change was not intentional, inspect the other actions taken by this actor.

Raw source GSuite Workspace Gmail Pre-Delivery Message Scanning Disabled · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Filename: gsuite_workspace_gmail_enhanced_predelivery_scanning.py
RuleID: "GSuite.Workspace.GmailPredeliveryScanningDisabled"
DisplayName: "GSuite Workspace Gmail Pre-Delivery Message Scanning Disabled"
Enabled: true
LogTypes:
  - GSuite.ActivityEvent
Tags:
  - GSuite
Reports:
  MITRE ATT&CK:
    - TA0001:T1566
Severity: Medium
Description: >
  A Workspace Admin Has Disabled Pre-Delivery Scanning For Gmail.
Reference: https://support.google.com/a/answer/7380368
Runbook: |
  Pre-delivery scanning is a feature in Gmail that subjects suspicious emails
  to additional automated scrutiny by Google.

  If this change was not intentional, inspect the other actions taken by this actor.
SummaryAttributes:
  - actor:email
Tests:
  - Name: Workspace Admin Disables Enhanced Pre-Delivery Scanning
    ExpectedResult: true
    Log:
      {
        "actor":
          {
            "callerType": "USER",
            "email": "example@example.io",
            "profileId": "12345",
          },
        "id":
          {
            "applicationName": "admin",
            "customerId": "D12345",
            "time": "2022-12-11 03:42:54.859000000",
            "uniqueQualifier": "-12345",
          },
        "ipAddress": "12.12.12.12",
        "kind": "admin#reports#activity",
        "name": "CHANGE_APPLICATION_SETTING",
        "parameters":
          {
            "APPLICATION_EDITION": "business_plus_2021",
            "APPLICATION_NAME": "Gmail",
            "NEW_VALUE": "true",
            "ORG_UNIT_NAME": "Example IO",
            "SETTING_NAME": "DelayedDeliverySettingsProto disable_delayed_delivery_for_suspicious_email",
          },
        "type": "APPLICATION_SETTINGS",
      }
  - Name: Admin Set Default Calendar SHARING_OUTSIDE_DOMAIN Setting to READ_ONLY_ACCESS
    ExpectedResult: false
    Log:
      {
        "actor":
          {
            "callerType": "USER",
            "email": "example@example.io",
            "profileId": "12345",
          },
        "id":
          {
            "applicationName": "admin",
            "customerId": "D12345",
            "time": "2022-12-11 01:06:26.303000000",
            "uniqueQualifier": "-12345",
          },
        "ipAddress": "12.12.12.12",
        "kind": "admin#reports#activity",
        "name": "CHANGE_CALENDAR_SETTING",
        "parameters":
          {
            "DOMAIN_NAME": "example.io",
            "NEW_VALUE": "READ_ONLY_ACCESS",
            "OLD_VALUE": "DEFAULT",
            "ORG_UNIT_NAME": "Example IO",
            "SETTING_NAME": "SHARING_OUTSIDE_DOMAIN",
          },
        "type": "CALENDAR_SETTINGS",
      }
  - Name: ListObject Type
    ExpectedResult: false
    Log:
      {
        "actor":
          { "email": "user@example.io", "profileId": "118111111111111111111" },
        "id":
          {
            "applicationName": "drive",
            "customerId": "D12345",
            "time": "2022-12-20 17:27:47.080000000",
            "uniqueQualifier": "-7312729053723258069",
          },
        "ipAddress": "12.12.12.12",
        "kind": "admin#reports#activity",
        "name": "rename",
        "parameters":
          {
            "actor_is_collaborator_account": null,
            "billable": true,
            "doc_id": "1GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG",
            "doc_title": "Document Title- Found Here",
            "doc_type": "presentation",
            "is_encrypted": null,
            "new_value": ["Document Title- Found Here"],
            "old_value": ["Document Title- Old"],
            "owner": "user@example.io",
            "owner_is_shared_drive": null,
            "owner_is_team_drive": null,
            "primary_event": true,
            "visibility": "private",
          },
        "type": "access",
      }


# ------ paired body: gsuite_workspace_gmail_enhanced_predelivery_scanning.py ------

from panther_gsuite_helpers import gsuite_activityevent_alert_context


def rule(event):
    # the shape of the items in parameters can change a bit ( like NEW_VALUE can be an array )
    #  when the applicationName is something other than admin
    if event.deep_get("id", "applicationName", default="").lower() != "admin":
        return False
    if all(
        [
            (event.get("name", "") == "CHANGE_APPLICATION_SETTING"),
            (event.deep_get("parameters", "APPLICATION_NAME", default="").lower() == "gmail"),
            (event.deep_get("parameters", "NEW_VALUE", default="").lower() == "true"),
            (
                event.deep_get("parameters", "SETTING_NAME", default="")
                == "DelayedDeliverySettingsProto disable_delayed_delivery_for_suspicious_email"
            ),
        ]
    ):
        return True
    return False


def title(event):
    return (
        f"GSuite Gmail Enhanced Pre-Delivery Scanning was disabled "
        f"for [{event.deep_get('parameters', 'ORG_UNIT_NAME', default='<NO_ORG_UNIT_NAME>')}] "
        f"by [{event.deep_get('actor', 'email', default='<UNKNOWN_EMAIL>')}]"
    )


def alert_context(event):
    return gsuite_activityevent_alert_context(event)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.