detect-google-workspace-suspicious-login
Installation
SKILL.md
detect-google-workspace-suspicious-login
Attack pattern
This skill covers one narrow Workspace identity pattern with two verified entry paths:
- Google Workspace already marks the login event as suspicious via the
is_suspiciouslogin audit parameter - a short burst of repeated
login_failureevents followed by onelogin_successfor the same user and source IP inside a 10-minute window
That second path is intentionally conservative. It does not attempt impossible travel, geovelocity, or every login anomaly in the catalog.