1Password - Changes to SSO configuration
| Id | 9406f5ab-1197-4db9-8042-9f3345be061c |
| Rulename | 1Password - Changes to SSO configuration |
| Description | This will alert when changes have been made to the SSO configuration. Once this analytics rule is triggered it will group all related future alerts for upto an hour when all related entities are the same. Ref: https://1password.com/ Ref: https://github.com/securehats/ |
| Severity | Medium |
| Tactics | Persistence |
| Techniques | T1556 |
| Required data connectors | 1Password |
| Kind | Scheduled |
| Query frequency | 5m |
| Query period | 5m |
| Trigger threshold | 0 |
| Trigger operator | gt |
| Source Uri | https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/1Password/Analytics Rules/1Password - Changes to SSO configuration.yaml |
| Version | 1.0.1 |
| Arm template | 9406f5ab-1197-4db9-8042-9f3345be061c.json |
OnePasswordEventLogs_CL
| where log_source == "auditevents"
| where action has_any("enblsso", "disblsso", "chngpsso", "chngasso", "chngdsso", "addgsso", "delgsso")
| where object_type == "sso"
| extend
ActorUsername = actor_details.email
, SrcIpAddr = session.ip
name: 1Password - Changes to SSO configuration
alertDetailsOverride:
alertDynamicProperties: []
entityMappings:
- fieldMappings:
- columnName: ActorUsername
identifier: FullName
entityType: Account
- fieldMappings:
- columnName: SrcIpAddr
identifier: Address
entityType: IP
version: 1.0.1
description: |-
This will alert when changes have been made to the SSO configuration. Once this analytics rule is triggered it will group all related future alerts for upto an hour when all related entities are the same.
Ref: https://1password.com/
Ref: https://github.com/securehats/
triggerThreshold: 0
suppressionEnabled: false
id: 9406f5ab-1197-4db9-8042-9f3345be061c
triggerOperator: gt
query: |-
OnePasswordEventLogs_CL
| where log_source == "auditevents"
| where action has_any("enblsso", "disblsso", "chngpsso", "chngasso", "chngdsso", "addgsso", "delgsso")
| where object_type == "sso"
| extend
ActorUsername = actor_details.email
, SrcIpAddr = session.ip
tactics:
- Persistence
suppressionDuration: 5h
kind: Scheduled
queryFrequency: 5m
severity: Medium
incidentConfiguration:
createIncident: true
groupingConfiguration:
lookbackDuration: 1h
reopenClosedIncident: false
matchingMethod: AllEntities
enabled: true
queryPeriod: 5m
requiredDataConnectors:
- dataTypes:
- OnePasswordEventLogs_CL
connectorId: 1Password
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/1Password/Analytics Rules/1Password - Changes to SSO configuration.yaml
eventGroupingSettings:
aggregationKind: SingleAlert
relevantTechniques:
- T1556