ingest-google-workspace-login-ocsf

Installation
SKILL.md

ingest-google-workspace-login-ocsf

Convert verified Google Workspace Admin SDK Reports login audit payloads into OCSF 1.8 IAM records by default, or the repo-owned native IAM projection when --output-format native is selected.

Use when

  • You have Admin SDK Reports activities.list exports for applicationName=login and need OCSF output
  • You want to normalize Google Workspace login and 2-step-verification telemetry for SIEM, lake, MCP, or downstream detection use
  • You need a portable identity event stream that preserves Workspace id.time, id.uniqueQualifier, actor IDs, and raw login parameters
  • You want Workspace identity events represented as OCSF before feeding them into cross-vendor detections or evidence flows

Do NOT use

  • On Google Cloud Audit Logs, Cloud Identity logs, or raw Entra / Okta payloads
  • To collect live Workspace audit data by itself — upstream collection and auth stay outside this skill
  • To infer ATT&CK techniques or create findings directly
  • To mutate Workspace users, sessions, or 2-step settings
Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
ingest-google-workspace-login-ocsf — msaad00/cloud-ai-security-skills