OneLogin user viewed secure note
Set up the onelogin integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when a OneLogin user views a secure note.
Strategy
This rule lets you monitor the following OneLogin events to detect when a user views a secure note:
@evt.name:PRIVILEGE_GRANTED_TO_USER
This rule is useful when correlating its findings with other anomalous events from the same OneLogin user ({{@actor_user_name}}
).
Triage and response
- Determine whether the OneLogin user (
{{@actor_user_name}}
) should be legitimately accessing secure notes. - If the activity was not legitimate, review all activity from
{{@actor_user_name}}
and the IP ({{@network.client.ip}}
) associated with this signal.