CyberCLI
← All connectors

Google Workspace

Coming soon Pro

Cloud Identity & Email

The Google-shop identity + Drive perimeter, in your SOC.

Google Workspace homepage ↗

The Google-shop equivalent of the M365 lane. Admin SDK Reports API delivers login, drive, mobile, and token activity into your CyberCLI case lifecycle.

What it watches

  • Login activity — failed, suspicious, new-location sign-ins
  • Admin-console actions — role, sharing, and OU changes
  • Drive activity — mass-download, external-share, ownership transfer
  • OAuth-token grants to third-party apps
  • Mobile + device events

MITRE ATT&CK coverage

Tactics this connector gives CyberCLI visibility into.

TA0001 · Initial Access TA0005 · Defense Evasion TA0006 · Credential Access TA0007 · Discovery TA0008 · Lateral Movement TA0009 · Collection
See the full coverage matrix →

What it helps you catch

Catches a compromised account by the impossible-travel login before data walks out the door.
Flags a mass external-share or ownership transfer on Drive — the exfil pattern for a Google shop.
Surfaces a risky OAuth grant to a third-party app that quietly reads all mail + files.

What you'd see in CyberCLI

illustrative
CYCON 3 high Google Workspace

Catches a compromised account by the impossible-travel login before data walks out the door.

Routed to Warden (triage) → Knight (detection) → Marshal (response) → Herald (notify)

⛓ every step hash-chained · replayable

Close more of the kill chain

Google Workspace covers 6 of 14 ATT&CK tactics. Pair it with these to widen coverage:

How to connect

On the roadmap — not yet shipped

Google Workspace is on the connector roadmap but not yet bundled. The plan above describes what we'll ingest + how it maps to MITRE; install instructions land when the connector pack ships.

Tell us you'd use it →  Pro tier customers get priority on connector prioritisation.

Guild roles it feeds
  • Warden (triage)
  • Knight (detection)
  • Marshal (response)
  • Herald (notify)
The Guild →
Sovereignty

Hybrid. Workspace audit data is pulled via Google's API into your local SOC — correlated under your control.

Go deeper