Cisco Duo bypass code is used to authenticate user request
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when a Duo bypass code is used to authenticate a user request.
Strategy
This rule monitors successful authentication events in Cisco Duo logs where the reason is set to bypass_user
.
Triage and Response
- Contact the user
{{@usr.email}}
to confirm they used the bypass code. - If the user is unaware, investigate the authentication event, focusing on the IP address
{{@access_device.ip}}
, application {{@application.name}}
, and user {{@usr.email}}
involved. - If the event is deemed malicious, begin your organization’s incident response process to contain the affected account or device.