Gmail
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Source-only rules that filter on applicationName 'gmail' without specifying an eventName attribute here. | N | Y |
| delivery | A Gmail message delivery event. The event_info.mail_event_type parameter sub-classifies into receive, send, bounce, and other delivery outcomes. | N | N |
any: Gmail (any event)
#Description
Source-only rules that filter on applicationName 'gmail' without specifying an eventName attribute here.
Detection Fields #
Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.
| Name | Rules | Vendors |
|---|---|---|
id.applicationName | 7 detection rules | Panther |
parameters.message_info.is_spam | 3 detection rules | Panther |
parameters.event_info.mail_event_type | 2 detection rules | Panther |
actor.email | 1 detection rule | Panther |
parameters.event_info.success | 1 detection rule | Panther |
parameters.message_info.attachment.malware_family | 1 detection rule | Panther |
parameters.message_info.connection_info.dkim_pass | 1 detection rule | Panther |
parameters.message_info.connection_info.dmarc_pass | 1 detection rule | Panther |
parameters.message_info.connection_info.spf_pass | 1 detection rule | Panther |
parameters.message_info.message_set.type | 1 detection rule | Panther |
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
parameters.message_info.is_spam (panther rule field) | eq | true | 3 rules | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1204.002, T1566.001T1566T1204.001, T1566.002