Atlassian user invited to organization as an organization administrator

Set up the atlassian-event-logs integration.

Goal

Detect when an Atlassian user is invited to the organization with the organizational administrator role.

Strategy

This rule monitors Atlassian organization audit logs for when a user is invited to the organization with the organizational administrator role. An attacker may try to invite an additional identity to the organization with high-level privileges.

Triage and response

  1. Determine if the user {{@usr.email}} intended to invite the target user as an organizational administrator:
    • Is there a related ticket tracking this change?
    • Is {{@usr.email}} aware of this activity?
    • Is the network metadata associated with the activity unusual for this user?
  2. If the results of the triage indicate that {{@usr.email}} was not aware of this activity or it did not originate from a known network, begin your company’s incident response process, and start an investigation.
PREVIEWING: guacbot/translation-pipeline