← All controls

68 Detection engineering on exported logs

draft

Scheduled Sigma rules or BigQuery SQL run over the exported audit logs (33 Audit-log export to SIEM/BigQuery), one rule per hypothesis, version-controlled, each with a documented false-positive rate: an OAuth grant to a new client id, a domain-wide delegation change, a mass Drive download, an admin role grant, a forwarding rule added. These are the API-level attacks no console screen shows you, and the hits are routed into the same alert pipeline the heartbeat (№54) proves is alive.

Caveats

Setup steps

  1. One rule
    one hypothesis, version-controlled, with a documented false-positive rate
  2. Scheduled query cadence
    15min–1h depending on the rule

Ongoing maintenance

How to verify

  1. Replay a known-bad event pattern (e.g. a mass-download simulation from a test account) into the pipeline and confirm the detection fires end to end — the query alone proves nothing.

draft v0.0.3 Detect edition Ent/Edu/Frontline Std+, Ent Essentials Plus policy #33 · #18 ↗