detect-google-workspace-suspicious-login

Installation
SKILL.md

detect-google-workspace-suspicious-login

Attack pattern

This skill covers one narrow Workspace identity pattern with two verified entry paths:

  • Google Workspace already marks the login event as suspicious via the is_suspicious login audit parameter
  • a short burst of repeated login_failure events followed by one login_success for the same user and source IP inside a 10-minute window

That second path is intentionally conservative. It does not attempt impossible travel, geovelocity, or every login anomaly in the catalog.

Detection logic

Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
detect-google-workspace-suspicious-login — msaad00/cloud-ai-security-skills