1Password-Account
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| any | Account (catch-all) | _catch_all | N | N |
| account-activate | Activate Account | account-activate | N | N |
| account-convert | Change Account Type | account-convert | N | N |
| account-delete | Delete Account | account-delete | N | N |
| account-disblduo | Disable Duo | account-disblduo | N | N |
| account-disblmfa | Disable Multi-Factor Authentication For All Users | account-disblmfa | N | Y |
| account-dvrfydmn | Delete Verified Domain | account-dvrfydmn | N | N |
| account-enblduo | Enable Duo | account-enblduo | N | N |
| account-uisas | Update Item Share Settings | account-uisas | Y | N |
| account-updatduo | Update Duo Configuration | account-updatduo | N | N |
| account-update | Update Account | account-update | Y | N |
| account-updatfw | Update Firewall Rules | account-updatfw | Y | Y |
| account-uvrfydmn | Update Verified Domain | account-uvrfydmn | N | N |
| account-vrfydmn | Add Verified Domain | account-vrfydmn | N | N |
any: Account (catch-all)
#Description
Catch-all entry for 1Password rules that match account events without naming a specific action.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
account-activate: Activate Account
#Description
The account was activated.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
account-convert: Change Account Type
#Description
The account type was changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
account-delete: Delete Account
#Description
The account was deleted.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
account-disblduo: Disable Duo
#Description
Duo was disabled for the account.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
account-disblmfa: Disable Multi-Factor Authentication For All Users
#Description
Multi-factor authentication was disabled for everyone in the account.
Fields #
| Name | Description | Rules |
|---|---|---|
uuid | The unique identifier for the event. | |
timestamp | When the action was performed. | |
actor_uuid | The unique identifier for the team member who performed the action. | |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). | |
actor_details.name | Full name | |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). | |
actor_type | ||
actor_account_uuid | ||
account_uuid | ||
action | The type of action that was performed. | 1 detection rule |
object_type | The type of object that the action was performed on. | 1 detection rule |
object_uuid | The unique identifier for the object the action was performed on. | |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. | |
object_details.name | Full name | |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. | |
aux_id | The identifier that relates to additional information about the activity. | |
aux_uuid | The unique identifier that relates to additional information about the activity. | |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. | |
aux_details.name | Full name | |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. | |
aux_info | Additional information about the activity. | |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
log_source (kusto rule field) | eq | auditevents | 1 rule | kusto |
object_type (kusto rule field) | eq | account | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1556
account-dvrfydmn: Delete Verified Domain
#Description
A verified domain was removed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
account-enblduo: Enable Duo
#Description
Duo was enabled for the account.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
account-uisas: Update Item Share Settings
#Description
The account's item sharing settings were updated.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "C3K75ZPF73XTL35XTJRGSRICCV",
"timestamp": "1/15/2024, 12:30:25.011 PM",
"location": {
"country": "The Netherlands",
"region": "Utrecht",
"city": "Amersfoort",
"latitude": 52.1849,
"longitude": 5.3954
},
"actor_uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
"actor_details": {
"uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
"name": "Tommy Shelby",
"email": "tommy.shelby@securehats.nl"
},
"action": "uisas",
"object_type": "account",
"object_uuid": "KFBHWWBES5FMZOL4DEO4ZADXHY",
"session": {
"uuid": "TNAMIDWR2FFZPAFJNO6PQKLKYY",
"login_time": "2024-01-15T12:29:09.3172584Z",
"device_uuid": "tmikosahabjierhqhaapybduj4",
"ip": "80.114.2.247"
}
}
account-updatduo: Update Duo Configuration
#Description
The Duo configuration for the account was updated.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
account-update: Update Account
#Description
Account attributes, such as the name, were changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "WYCP25RNDPNYCF5K4XRJ2CFH65",
"timestamp": "12/15/2023, 10:08:50.120 AM",
"location": {
"country": "The Netherlands",
"region": "North Holland",
"city": "Amsterdam",
"latitude": 52.3759,
"longitude": 4.8975
},
"actor_uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
"actor_details": {
"uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
"name": "Tommy Shelby",
"email": "tommy.shelby@securehats.nl"
},
"action": "update",
"object_type": "account",
"object_uuid": "KFBHWWBES5FMZOL4DEO4ZADXHY",
"session": {
"uuid": "LYLWMPH245GGLEE5T5GULX7FRU",
"login_time": "2023-12-15T10:08:15.5397096Z",
"device_uuid": "wnxznnlchyi4cpqratg6dzigjq",
"ip": "193.187.128.72"
}
}
account-updatfw: Update Firewall Rules
#Description
A firewall rule was added or updated.
Fields #
| Name | Description | Rules |
|---|---|---|
uuid | The unique identifier for the event. | |
timestamp | When the action was performed. | |
actor_uuid | The unique identifier for the team member who performed the action. | |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). | |
actor_details.name | Full name | |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). | |
actor_type | ||
actor_account_uuid | ||
account_uuid | ||
action | The type of action that was performed. | 1 detection rule |
object_type | The type of object that the action was performed on. | 1 detection rule |
object_uuid | The unique identifier for the object the action was performed on. | |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. | |
object_details.name | Full name | |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. | |
aux_id | The identifier that relates to additional information about the activity. | |
aux_uuid | The unique identifier that relates to additional information about the activity. | |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. | |
aux_details.name | Full name | |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. | |
aux_info | Additional information about the activity. | |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "ZIKGWQ2RLEE47TM36ZGLJ767GT",
"timestamp": "1/15/2024, 1:40:30.743 PM",
"location": {
"country": "The Netherlands",
"region": "Utrecht",
"city": "Amersfoort",
"latitude": 52.1849,
"longitude": 5.3954
},
"actor_uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
"actor_details": {
"uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
"name": "Tommy Shelby",
"email": "tommy.shelby@securehats.nl"
},
"action": "updatfw",
"object_type": "account",
"object_uuid": "KFBHWWBES5FMZOL4DEO4ZADXHY",
"session": {
"uuid": "TNAMIDWR2FFZPAFJNO6PQKLKYY",
"login_time": "2024-01-15T12:29:09.3172584Z",
"device_uuid": "tmikosahabjierhqhaapybduj4",
"ip": "80.114.2.247"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
log_source (kusto rule field) | eq | auditevents | 1 rule | kusto |
object_type (kusto rule field) | eq | account | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1562
account-uvrfydmn: Update Verified Domain
#Description
A verified domain was updated.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
account-vrfydmn: Add Verified Domain
#Description
A domain was verified.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |