Tailscale user approval configuration disabled
Set up the tailscale integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when the TailScale user approval configuration has been disabled.
Strategy
This rule monitors Tailscale logs for when the user approval configuration has been disabled. The user approval feature allows Tailscale network administrators to review and approve new users before they can join the network. An attacker disabling this could be an attempt to disable defenses.
Triage and response
- Investigate the user
{{@usr.email}}
that disabled user approval within your Tailscale configuration. - If the activity is deemed malicious:
- Begin your organization’s incident response process and investigate.