Unusual 1Password item usage action observed from user

1password

Classification:

attack

Set up the 1password integration.

Goal

Detect when 1Password item usage activity is observed.

Strategy

This rule monitors 1Password audit logs for the following item usage actions

Note: This rule uses the New Value detection method, to determine when a previously unseen item usage action is observed.

Triage & response

Investigate {{@usr.email}} attempting an item usage action: {{@evt.name}} that they haven’t performed recently with item {{@item_uuid}} within vault {{@vault_uuid}}.

PREVIEWING: may/unit-testing