GSuite Workspace Gmail Security Sandbox Disabled


Description

A Workspace Admin Has Disabled The Security Sandbox

Query · python

from panther_gsuite_helpers import gsuite_activityevent_alert_context


def rule(event):
    if event.deep_get("id", "applicationName", default="").lower() != "admin":
        return False
    if all(
        [
            (event.get("name", "") == "CHANGE_APPLICATION_SETTING"),
            (event.deep_get("parameters", "APPLICATION_NAME", default="").lower() == "gmail"),
            (event.deep_get("parameters", "NEW_VALUE", default="").lower() == "false"),
            (
                event.deep_get("parameters", "SETTING_NAME", default="")
                == "AttachmentDeepScanningSettingsProto deep_scanning_enabled"
            ),
        ]
    ):
        return True
    return False


def title(event):
    return (
        f"GSuite Gmail Security Sandbox was disabled "
        f"for [{event.deep_get('parameters', 'ORG_UNIT_NAME', default='<NO_ORG_UNIT_NAME>')}] "
        f"by [{event.deep_get('actor', 'email', default='<UNKNOWN_EMAIL>')}]"
    )


def alert_context(event):
    return gsuite_activityevent_alert_context(event)

Analyst notes

Gmail's Security Sandbox enables rule based scanning of email content. If this change was not intentional, inspect the other actions taken by this actor.

Raw source GSuite Workspace Gmail Security Sandbox Disabled · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Filename: gsuite_workspace_gmail_security_sandbox_disabled.py
RuleID: "GSuite.Workspace.GmailSecuritySandboxDisabled"
DisplayName: "GSuite Workspace Gmail Security Sandbox Disabled"
Enabled: true
LogTypes:
  - GSuite.ActivityEvent
Tags:
  - GSuite
Reports:
  MITRE ATT&CK:
    - TA0001:T1566
Severity: Medium
Description: >
  A Workspace Admin Has Disabled The Security Sandbox
Reference: https://support.google.com/a/answer/7676854?hl=en#zippy=%2Cfind-security-sandbox-settings%2Cabout-security-sandbox-rules-and-other-scans
Runbook: >
  Gmail's Security Sandbox enables rule based scanning of email content.

  If this change was not intentional, inspect the other actions taken by this actor.
SummaryAttributes:
  - actor:email
Tests:
  - Name: Workspace Admin Disables Security Sandbox
    ExpectedResult: true
    Log:
      {
        "actor":
          {
            "callerType": "USER",
            "email": "example@example.io",
            "profileId": "12345",
          },
        "id":
          {
            "applicationName": "admin",
            "customerId": "D12345",
            "time": "2022-12-11 03:31:41.212000000",
            "uniqueQualifier": "-12345",
          },
        "ipAddress": "12.12.12.12",
        "kind": "admin#reports#activity",
        "name": "CHANGE_APPLICATION_SETTING",
        "parameters":
          {
            "APPLICATION_EDITION": "enterprise",
            "APPLICATION_NAME": "Gmail",
            "NEW_VALUE": "false",
            "ORG_UNIT_NAME": "Example IO",
            "SETTING_NAME": "AttachmentDeepScanningSettingsProto deep_scanning_enabled",
          },
        "type": "APPLICATION_SETTINGS",
      }
  - Name: Admin Set Default Calendar SHARING_OUTSIDE_DOMAIN Setting to READ_ONLY_ACCESS
    ExpectedResult: false
    Log:
      {
        "actor":
          {
            "callerType": "USER",
            "email": "example@example.io",
            "profileId": "12345",
          },
        "id":
          {
            "applicationName": "admin",
            "customerId": "D12345",
            "time": "2022-12-11 01:06:26.303000000",
            "uniqueQualifier": "-12345",
          },
        "ipAddress": "12.12.12.12",
        "kind": "admin#reports#activity",
        "name": "CHANGE_CALENDAR_SETTING",
        "parameters":
          {
            "DOMAIN_NAME": "example.io",
            "NEW_VALUE": "READ_ONLY_ACCESS",
            "OLD_VALUE": "DEFAULT",
            "ORG_UNIT_NAME": "Example IO",
            "SETTING_NAME": "SHARING_OUTSIDE_DOMAIN",
          },
        "type": "CALENDAR_SETTINGS",
      }
  - Name: ListObject Type
    ExpectedResult: false
    Log:
      {
        "actor":
          { "email": "user@example.io", "profileId": "118111111111111111111" },
        "id":
          {
            "applicationName": "drive",
            "customerId": "D12345",
            "time": "2022-12-20 17:27:47.080000000",
            "uniqueQualifier": "-7312729053723258069",
          },
        "ipAddress": "12.12.12.12",
        "kind": "admin#reports#activity",
        "name": "rename",
        "parameters":
          {
            "actor_is_collaborator_account": null,
            "billable": true,
            "doc_id": "1GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG",
            "doc_title": "Document Title- Found Here",
            "doc_type": "presentation",
            "is_encrypted": null,
            "new_value": ["Document Title- Found Here"],
            "old_value": ["Document Title- Old"],
            "owner": "user@example.io",
            "owner_is_shared_drive": null,
            "owner_is_team_drive": null,
            "primary_event": true,
            "visibility": "private",
          },
        "type": "access",
      }


# ------ paired body: gsuite_workspace_gmail_security_sandbox_disabled.py ------

from panther_gsuite_helpers import gsuite_activityevent_alert_context


def rule(event):
    if event.deep_get("id", "applicationName", default="").lower() != "admin":
        return False
    if all(
        [
            (event.get("name", "") == "CHANGE_APPLICATION_SETTING"),
            (event.deep_get("parameters", "APPLICATION_NAME", default="").lower() == "gmail"),
            (event.deep_get("parameters", "NEW_VALUE", default="").lower() == "false"),
            (
                event.deep_get("parameters", "SETTING_NAME", default="")
                == "AttachmentDeepScanningSettingsProto deep_scanning_enabled"
            ),
        ]
    ):
        return True
    return False


def title(event):
    return (
        f"GSuite Gmail Security Sandbox was disabled "
        f"for [{event.deep_get('parameters', 'ORG_UNIT_NAME', default='<NO_ORG_UNIT_NAME>')}] "
        f"by [{event.deep_get('actor', 'email', default='<UNKNOWN_EMAIL>')}]"
    )


def alert_context(event):
    return gsuite_activityevent_alert_context(event)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.