1Password-GroupMembership
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| any | Group membership (catch-all) | _catch_all | N | Y |
| gm-join | Join Group | gm-join | Y | Y |
| gm-leave | Leave Group | gm-leave | Y | N |
| gm-role | Change Group Membership Role | gm-role | N | N |
any: Group membership (catch-all)
#Description
Catch-all entry for 1Password rules that match group membership events without naming a specific action.
Fields #
| Name | Description | Rules |
|---|---|---|
uuid | The unique identifier for the event. | |
timestamp | When the action was performed. | |
actor_uuid | The unique identifier for the team member who performed the action. | |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). | |
actor_details.name | Full name | |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). | |
actor_type | ||
actor_account_uuid | ||
account_uuid | ||
action | The type of action that was performed. | |
object_type | The type of object that the action was performed on. | 1 detection rule |
object_uuid | The unique identifier for the object the action was performed on. | |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. | |
object_details.name | Full name | |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. | |
aux_id | The identifier that relates to additional information about the activity. | |
aux_uuid | The unique identifier that relates to additional information about the activity. | |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. | |
aux_details.name | Full name | |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. | |
aux_info | Additional information about the activity. | 2 detection rules |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
log_source (kusto rule field) | eq | auditevents | 1 rule | kusto |
object_type (kusto rule field) | eq | gm | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078
gm-join: Join Group
#Description
A user joined a group.
Fields #
| Name | Description | Rules |
|---|---|---|
uuid | The unique identifier for the event. | |
timestamp | When the action was performed. | |
actor_uuid | The unique identifier for the team member who performed the action. | |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). | |
actor_details.name | Full name | |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). | |
actor_type | ||
actor_account_uuid | ||
account_uuid | ||
action | The type of action that was performed. | 1 detection rule |
object_type | The type of object that the action was performed on. | 1 detection rule |
object_uuid | The unique identifier for the object the action was performed on. | |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. | |
object_details.name | Full name | |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. | |
aux_id | The identifier that relates to additional information about the activity. | |
aux_uuid | The unique identifier that relates to additional information about the activity. | |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. | |
aux_details.name | Full name | |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. | |
aux_info | Additional information about the activity. | 2 detection rules |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "7IEPLBPSJX3N473UMJVQGS2UGW",
"timestamp": "12/15/2023, 10:54:41.356 AM",
"location": {
"country": "The Netherlands",
"region": "North Holland",
"city": "Amsterdam",
"latitude": 52.3759,
"longitude": 4.8975
},
"actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"actor_details": {
"uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"name": "Automated User Provisioning",
"email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
},
"action": "join",
"object_type": "gm",
"object_uuid": "l4oh2ghravchmzkuactjffwieu",
"aux_id": "11848060",
"aux_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"aux_details": {
"uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"name": "Automated User Provisioning",
"email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
},
"aux_info": "A",
"session": {
"uuid": "TPEFXHZ62ZGTHCHMSNEMLLDPMA",
"login_time": "2023-12-14T11:39:44.9931456Z",
"device_uuid": "pjleru42mvdhql4nl7mab6ympm",
"ip": "4.175.88.205"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
object_type (kusto rule field) | eq | gm | 1 rule | kusto |
object_uuid (kusto rule field) | eq | watchlist | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1098
gm-leave: Leave Group
#Description
A user left a group.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "CFHE6GAZKDOAEBV7JGVF7EJBFG",
"timestamp": "1/3/2024, 1:16:09.412 PM",
"location": {
"country": "The Netherlands",
"region": "North Brabant",
"city": "Rijen",
"latitude": 51.5923,
"longitude": 4.9218
},
"actor_uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
"actor_details": {
"uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
"name": "Walter White",
"email": "walter.white@securehats.nl"
},
"action": "leave",
"object_type": "gm",
"object_uuid": "mewjxg24s7mdhmel2akm73bway",
"aux_id": "11935842",
"aux_uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
"aux_details": {
"uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
"name": "Nigel Powers",
"email": "nigel.powers@securehats.nl"
},
"session": {
"uuid": "2JERYZS455CLZJFLYPUPLCAWYE",
"login_time": "2024-01-03T13:14:12.2688730Z",
"device_uuid": "uh7t35mrsnycrf4vz6wbdhs4y4",
"ip": "76.75.244.76"
}
}
gm-role: Change Group Membership Role
#Description
A user's group membership role was changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |