Google Workspace login activity: Out-of-domain email forwarding

Flags Google Workspace out-of-domain email forwarding events from audit logs on login.googleapis.com.

FreeReviewedSigma · Medium · v4
Product
gcp
Service
google_workspace.login
Author
Tom kluter (SigmaHQ), DRL 1.1
Published
2026-04-28
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Google Workspace events where email forwarding is automatically configured to send messages to domains outside the organization. Attackers can use this to exfiltrate data to accounts or services they control while keeping access within the email workflow. The detection relies on GCP/Google Workspace login activity telemetry that records the specific event name for out-of-domain email forwarding.

Related detections9 linkedT1114.003 — drag to rearrange
Suspicious Inbox Rule Creation With Forwarding or Deletion via M365 Exchange
Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
Malicious Mailbox Forwarding Rule Creation (via exchange)
Malicious Office 365 Email Forwarding Rule to External Domain (via office365)
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
O365 Mail Forwarding and Redirecting Rule Changes
Azure Risk Event: Suspicious Inbox Forwarding
Google Workspace login activity: Out-of-domain email forwarding
Pivot detection · T1114.003 · 9 related

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.