Gmail

eventNameDescriptionSampleRule
anySource-only rules that filter on applicationName 'gmail' without specifying an eventName attribute here.NY
deliveryA Gmail message delivery event. The event_info.mail_event_type parameter sub-classifies into receive, send, bounce, and other delivery outcomes.NN

any: Gmail (any event)

#
ApplicationName
gmail

Description

Source-only rules that filter on applicationName 'gmail' without specifying an eventName attribute here.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
id.applicationName7 detection rulesPanther
parameters.message_info.is_spam3 detection rulesPanther
parameters.event_info.mail_event_type2 detection rulesPanther
actor.email1 detection rulePanther
parameters.event_info.success1 detection rulePanther
parameters.message_info.attachment.malware_family1 detection rulePanther
parameters.message_info.connection_info.dkim_pass1 detection rulePanther
parameters.message_info.connection_info.dmarc_pass1 detection rulePanther
parameters.message_info.connection_info.spf_pass1 detection rulePanther
parameters.message_info.message_set.type1 detection rulePanther

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
parameters.message_info.is_spam (panther rule field)eqtrue3 rulespanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

delivery: Delivery

#
ApplicationName
gmail

Description

A Gmail message delivery event. The event_info.mail_event_type parameter sub-classifies into receive, send, bounce, and other delivery outcomes.

References #