Google Workspace
Coming soon ProCloud Identity & Email
The Google-shop identity + Drive perimeter, in your SOC.
Google Workspace homepage ↗The Google-shop equivalent of the M365 lane. Admin SDK Reports API delivers login, drive, mobile, and token activity into your CyberCLI case lifecycle.
What it watches
- Login activity — failed, suspicious, new-location sign-ins
- Admin-console actions — role, sharing, and OU changes
- Drive activity — mass-download, external-share, ownership transfer
- OAuth-token grants to third-party apps
- Mobile + device events
MITRE ATT&CK coverage
Tactics this connector gives CyberCLI visibility into.
What it helps you catch
What you'd see in CyberCLI
illustrativeCatches a compromised account by the impossible-travel login before data walks out the door.
Routed to Warden (triage) → Knight (detection) → Marshal (response) → Herald (notify)
⛓ every step hash-chained · replayable
Close more of the kill chain
Google Workspace covers 6 of 14 ATT&CK tactics. Pair it with these to widen coverage:
How to connect
Google Workspace is on the connector roadmap but not yet bundled. The plan above describes what we'll ingest + how it maps to MITRE; install instructions land when the connector pack ships.
Tell us you'd use it → Pro tier customers get priority on connector prioritisation.
Hybrid. Workspace audit data is pulled via Google's API into your local SOC — correlated under your control.