1Password-Account

EventTitleChannelSampleRule
anyAccount (catch-all)_catch_allNN
account-activateActivate Accountaccount-activateNN
account-convertChange Account Typeaccount-convertNN
account-deleteDelete Accountaccount-deleteNN
account-disblduoDisable Duoaccount-disblduoNN
account-disblmfaDisable Multi-Factor Authentication For All Usersaccount-disblmfaNY
account-dvrfydmnDelete Verified Domainaccount-dvrfydmnNN
account-enblduoEnable Duoaccount-enblduoNN
account-uisasUpdate Item Share Settingsaccount-uisasYN
account-updatduoUpdate Duo Configurationaccount-updatduoNN
account-updateUpdate Accountaccount-updateYN
account-updatfwUpdate Firewall Rulesaccount-updatfwYY
account-uvrfydmnUpdate Verified Domainaccount-uvrfydmnNN
account-vrfydmnAdd Verified Domainaccount-vrfydmnNN

any: Account (catch-all)

#

Description

Catch-all entry for 1Password rules that match account events without naming a specific action.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

account-activate: Activate Account

#

Description

The account was activated.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

account-convert: Change Account Type

#

Description

The account type was changed.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

account-delete: Delete Account

#

Description

The account was deleted.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

account-disblduo: Disable Duo

#

Description

Duo was disabled for the account.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

account-disblmfa: Disable Multi-Factor Authentication For All Users

#

Description

Multi-factor authentication was disabled for everyone in the account.

Fields #

NameDescriptionRules
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.1 detection rule
object_typeThe type of object that the action was performed on.1 detection rule
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
log_source (kusto rule field)eqauditevents1 rulekusto
object_type (kusto rule field)eqaccount1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

account-dvrfydmn: Delete Verified Domain

#

Description

A verified domain was removed.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

account-enblduo: Enable Duo

#

Description

Duo was enabled for the account.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

account-uisas: Update Item Share Settings

#

Description

The account's item sharing settings were updated.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

Example Event #

{
  "uuid": "C3K75ZPF73XTL35XTJRGSRICCV",
  "timestamp": "1/15/2024, 12:30:25.011 PM",
  "location": {
    "country": "The Netherlands",
    "region": "Utrecht",
    "city": "Amersfoort",
    "latitude": 52.1849,
    "longitude": 5.3954
  },
  "actor_uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
  "actor_details": {
    "uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
    "name": "Tommy Shelby",
    "email": "tommy.shelby@securehats.nl"
  },
  "action": "uisas",
  "object_type": "account",
  "object_uuid": "KFBHWWBES5FMZOL4DEO4ZADXHY",
  "session": {
    "uuid": "TNAMIDWR2FFZPAFJNO6PQKLKYY",
    "login_time": "2024-01-15T12:29:09.3172584Z",
    "device_uuid": "tmikosahabjierhqhaapybduj4",
    "ip": "80.114.2.247"
  }
}

account-updatduo: Update Duo Configuration

#

Description

The Duo configuration for the account was updated.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

account-update: Update Account

#

Description

Account attributes, such as the name, were changed.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

Example Event #

{
  "uuid": "WYCP25RNDPNYCF5K4XRJ2CFH65",
  "timestamp": "12/15/2023, 10:08:50.120 AM",
  "location": {
    "country": "The Netherlands",
    "region": "North Holland",
    "city": "Amsterdam",
    "latitude": 52.3759,
    "longitude": 4.8975
  },
  "actor_uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
  "actor_details": {
    "uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
    "name": "Tommy Shelby",
    "email": "tommy.shelby@securehats.nl"
  },
  "action": "update",
  "object_type": "account",
  "object_uuid": "KFBHWWBES5FMZOL4DEO4ZADXHY",
  "session": {
    "uuid": "LYLWMPH245GGLEE5T5GULX7FRU",
    "login_time": "2023-12-15T10:08:15.5397096Z",
    "device_uuid": "wnxznnlchyi4cpqratg6dzigjq",
    "ip": "193.187.128.72"
  }
}

account-updatfw: Update Firewall Rules

#

Description

A firewall rule was added or updated.

Fields #

NameDescriptionRules
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.1 detection rule
object_typeThe type of object that the action was performed on.1 detection rule
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

Example Event #

{
  "uuid": "ZIKGWQ2RLEE47TM36ZGLJ767GT",
  "timestamp": "1/15/2024, 1:40:30.743 PM",
  "location": {
    "country": "The Netherlands",
    "region": "Utrecht",
    "city": "Amersfoort",
    "latitude": 52.1849,
    "longitude": 5.3954
  },
  "actor_uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
  "actor_details": {
    "uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
    "name": "Tommy Shelby",
    "email": "tommy.shelby@securehats.nl"
  },
  "action": "updatfw",
  "object_type": "account",
  "object_uuid": "KFBHWWBES5FMZOL4DEO4ZADXHY",
  "session": {
    "uuid": "TNAMIDWR2FFZPAFJNO6PQKLKYY",
    "login_time": "2024-01-15T12:29:09.3172584Z",
    "device_uuid": "tmikosahabjierhqhaapybduj4",
    "ip": "80.114.2.247"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
log_source (kusto rule field)eqauditevents1 rulekusto
object_type (kusto rule field)eqaccount1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

account-uvrfydmn: Update Verified Domain

#

Description

A verified domain was updated.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

account-vrfydmn: Add Verified Domain

#

Description

A domain was verified.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

References #