NordPassEventLogs_CL
| where event_type == "item_delete"
| where action == "item_reassignment_deleted"
| extend TargetEmail = user_email
description: |
This will alert you if the deleted user's items have been removed without being transferred to another active user, as this could result in the loss of access to critical tools or information.
tactics:
- Impact
requiredDataConnectors:
- dataTypes:
- NordPassEventLogs_CL
connectorId: NordPass
incidentConfiguration:
createIncident: false
id: 0068dca4-dea0-46a3-a970-655e067a145f
severity: High
query: |
NordPassEventLogs_CL
| where event_type == "item_delete"
| where action == "item_reassignment_deleted"
| extend TargetEmail = user_email
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/NordPass/Analytics Rules/nordpass_items_reassignment_deletion.yaml
kind: Scheduled
queryPeriod: 5m
displayName: Deleting items of deleted member
name: NordPass - Deleting items of deleted member
queryFrequency: 5m
triggerThreshold: 0
relevantTechniques:
- T1485
version: 1.0.0
entityMappings:
- entityType: Mailbox
fieldMappings:
- identifier: MailboxPrimaryAddress
columnName: TargetEmail
triggerOperator: gt