1Password - Disable MFA factor or type for all user accounts
| Id | 92ab0938-1e7c-4671-9810-392e8b9714da |
| Rulename | 1Password - Disable MFA factor or type for all user accounts |
| Description | This will alert when the MFA factor or type for all user accounts are disabled. Once this analytics rule is triggered it will group all related future alerts for upto an hour when all related entities are the same. Ref: https://1password.com/ Ref: https://github.com/securehats/ |
| Severity | High |
| Tactics | DefenseEvasion |
| Techniques | T1556 |
| Required data connectors | 1Password |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 5m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/1Password/Analytics Rules/1Password - Disable MFA factor or type for all user accounts.yaml |
| Version | 1.0.0 |
| Arm template | 92ab0938-1e7c-4671-9810-392e8b9714da.json |
OnePasswordEventLogs_CL
| where log_source == "auditevents"
| where action == "disblmfa"
| where object_type == "account"
| extend
ActorUsername = actor_details.email
, SrcIpAddr = session.ip
entityMappings:
- entityType: Account
fieldMappings:
- columnName: ActorUsername
identifier: FullName
- entityType: IP
fieldMappings:
- columnName: SrcIpAddr
identifier: Address
description: |-
This will alert when the MFA factor or type for all user accounts are disabled. Once this analytics rule is triggered it will group all related future alerts for upto an hour when all related entities are the same.
Ref: https://1password.com/
Ref: https://github.com/securehats/
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/1Password/Analytics Rules/1Password - Disable MFA factor or type for all user accounts.yaml
requiredDataConnectors:
- dataTypes:
- OnePasswordEventLogs_CL
connectorId: 1Password
eventGroupingSettings:
aggregationKind: SingleAlert
query: |-
OnePasswordEventLogs_CL
| where log_source == "auditevents"
| where action == "disblmfa"
| where object_type == "account"
| extend
ActorUsername = actor_details.email
, SrcIpAddr = session.ip
triggerThreshold: 0
name: 1Password - Disable MFA factor or type for all user accounts
relevantTechniques:
- T1556
suppressionDuration: 5h
incidentConfiguration:
groupingConfiguration:
reopenClosedIncident: false
enabled: true
matchingMethod: AllEntities
lookbackDuration: 1h
createIncident: true
tactics:
- DefenseEvasion
queryPeriod: 5m
severity: High
kind: Scheduled
suppressionEnabled: false
queryFrequency: 5m
id: 92ab0938-1e7c-4671-9810-392e8b9714da
version: 1.0.0
triggerOperator: gt