1Password-User
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| any | User (catch-all) | _catch_all | N | Y |
| user-activate | Change User State From | user-activate | Y | N |
| user-beginr | Change User State From | user-beginr | Y | N |
| user-cancelr | Cancel User Recovery | user-cancelr | N | N |
| user-changeks | Change User Keyset | user-changeks | N | N |
| user-changela | Change Language | user-changela | N | N |
| user-changemp | Change 1Password Account Password | user-changemp | N | N |
| user-changenm | Change Name | user-changenm | Y | N |
| user-changesk | Change Secret Key | user-changesk | N | N |
| user-completr | Complete User Recovery | user-completr | Y | N |
| user-dealldev | Delete All Devices | user-dealldev | Y | N |
| user-delete | Change User State From | user-delete | Y | Y |
| user-deolddev | Delete Old Devices | user-deolddev | N | N |
| user-disblmfa | Disable Multi-Factor Authentication | user-disblmfa | Y | N |
| user-enblmfa | Enable Multi-Factor Authentication | user-enblmfa | Y | N |
| user-join | Change User State From | user-join | N | N |
| user-provsn | Provision (User) | user-provsn | Y | N |
| user-reactive | Change User State From | user-reactive | Y | N |
| user-resendts | Resend Provisioning Email | user-resendts | Y | N |
| user-sdvcsso | Set up Single Sign-On Authentication | user-sdvcsso | N | N |
| user-sendpkg | Send Package | user-sendpkg | N | N |
| user-sendts | Send Provisioning Email | user-sendts | Y | N |
| user-suspend | Change User State From | user-suspend | Y | Y |
| user-tdvcsso | Enroll Trusted Device | user-tdvcsso | Y | N |
| user-trvlaway | Mark User Away For Travel | user-trvlaway | N | N |
| user-trvlback | Mark User Back From Travel | user-trvlback | N | N |
| user-updatmfa | Update Multi-Factor Authentication | user-updatmfa | Y | N |
| user-upguest | Upgrade User | user-upguest | N | N |
| user-verify | Change User State From | user-verify | N | N |
any: User (catch-all)
#Description
Catch-all entry for 1Password rules that match user events without naming a specific action.
Fields #
| Name | Description | Rules |
|---|---|---|
uuid | The unique identifier for the event. | |
timestamp | When the action was performed. | |
actor_uuid | The unique identifier for the team member who performed the action. | |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). | |
actor_details.name | Full name | |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). | |
actor_type | ||
actor_account_uuid | ||
account_uuid | ||
action | The type of action that was performed. | |
object_type | The type of object that the action was performed on. | 1 detection rule |
object_uuid | The unique identifier for the object the action was performed on. | |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. | |
object_details.name | Full name | |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. | |
aux_id | The identifier that relates to additional information about the activity. | |
aux_uuid | The unique identifier that relates to additional information about the activity. | |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. | |
aux_details.name | Full name | |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. | |
aux_info | Additional information about the activity. | |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. | |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. | |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
object_type (kusto rule field) | eq | user | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1556
user-activate: Change User State From
#Description
A user's state was changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "GRXST7MM2VJIDNDOTI5XZKXFON",
"timestamp": "12/15/2023, 11:05:51.266 AM",
"location": {
"country": "The Netherlands",
"region": "North Holland",
"city": "Amsterdam",
"latitude": 52.3759,
"longitude": 4.8975
},
"actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"actor_details": {
"uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"name": "Automated User Provisioning",
"email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
},
"action": "activate",
"object_type": "user",
"object_uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
"object_details": {
"uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
"name": "Arthur Shelby",
"email": "arthur.shelby@securehats.nl"
},
"session": {
"uuid": "KRG6S6ANAZB67JYNUQFNTMZQ6Y",
"login_time": "2023-12-12T05:25:28.4465411Z",
"device_uuid": "pjleru42mvdhql4nl7mab6ympm",
"ip": "4.175.88.205"
}
}
user-beginr: Change User State From
#Description
A user's state was changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "BV4MOQ2K7BSKBWCJR4YYVYFFGC",
"timestamp": "12/15/2023, 11:26:23.804 AM",
"location": {
"country": "The Netherlands",
"region": "North Brabant",
"city": "Rijen",
"latitude": 51.5923,
"longitude": 4.9218
},
"actor_uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
"actor_details": {
"uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
"name": "Walter White",
"email": "walter.white@securehats.nl"
},
"action": "beginr",
"object_type": "user",
"object_uuid": "KQIRZOBQP5DIHDDHEWTC375IF4",
"object_details": {
"uuid": "KQIRZOBQP5DIHDDHEWTC375IF4",
"name": "Bryan Beekhof",
"email": "bryan.beekhof@securehats.nl"
},
"session": {
"uuid": "3AZWUJUQMBAOVHBUM246E3EWGU",
"login_time": "2023-12-15T11:25:29.6672894Z",
"device_uuid": "uh7t35mrsnycrf4vz6wbdhs4y4",
"ip": "76.75.244.76"
}
}
user-cancelr: Cancel User Recovery
#Description
A user recovery was canceled.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-changeks: Change User Keyset
#Description
A user's keyset changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-changela: Change Language
#Description
A user changed their preferred language.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-changemp: Change 1Password Account Password
#Description
A user changed their 1Password account password.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-changenm: Change Name
#Description
A user changed their name.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "DUMMY-ID-0055",
"action": "changenm",
"session": {
"uuid": "DUMMY-ID-0056",
"login_time": "2026-08-20T14:43:23.780889197Z",
"device_uuid": "DUMMY-ID-0003",
"ip": "192.0.2.1"
},
"location": {
"country": "Dummy Country 001",
"region": "Dummy Region 001",
"city": "Dummy City 001",
"latitude": 0.0,
"longitude": 0.0
},
"timestamp": "2026-08-20T17:57:23.693528547Z",
"actor_type": "user",
"actor_uuid": "DUMMY-USER-0001",
"object_type": "user",
"object_uuid": "DUMMY-USER-0020",
"account_uuid": "DUMMY-ID-0004",
"actor_details": {
"uuid": "DUMMY-USER-0001",
"name": "Dummy User 001",
"email": "dummy.user001@example.invalid"
},
"object_details": {
"uuid": "DUMMY-USER-0020",
"name": "Dummy User 020",
"email": "dummy.user020@example.invalid"
}
}
user-changesk: Change Secret Key
#Description
A user changed their Secret Key.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-completr: Complete User Recovery
#Description
A user recovery was completed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "N7CPROXEZV65ZSJ5XVJNQQKAKR",
"timestamp": "1/3/2024, 2:42:28.173 PM",
"location": {
"country": "The Netherlands",
"region": "North Brabant",
"city": "Rijen",
"latitude": 51.5923,
"longitude": 4.9218
},
"actor_uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
"actor_details": {
"uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
"name": "Walter White",
"email": "walter.white@securehats.nl"
},
"action": "completr",
"object_type": "user",
"object_uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
"object_details": {
"uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
"name": "Nigel Powers",
"email": "nigel.powers@securehats.nl"
},
"session": {
"uuid": "5NP22Y4FMJAMPO7ZYZMUO6GG6E",
"login_time": "2024-01-03T14:29:23.9986687Z",
"device_uuid": "uh7t35mrsnycrf4vz6wbdhs4y4",
"ip": "76.75.244.76"
}
}
user-dealldev: Delete All Devices
#Description
All devices were deleted.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "E5F5CT443DDB2JCS4A7GB5XHW2",
"timestamp": "12/15/2023, 11:10:37.524 AM",
"location": {
"country": "The Netherlands",
"region": "North Holland",
"city": "Amsterdam",
"latitude": 52.3759,
"longitude": 4.8975
},
"actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"actor_details": {
"uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"name": "Automated User Provisioning",
"email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
},
"action": "dealldev",
"object_type": "user",
"object_uuid": "AONGS2F7BFFPNG2LBTFMRH562Q",
"object_details": {
"uuid": "AONGS2F7BFFPNG2LBTFMRH562Q",
"name": "Gideon Wories",
"email": "gideon.wories@securehats.nl"
},
"session": {
"uuid": "TPEFXHZ62ZGTHCHMSNEMLLDPMA",
"login_time": "0001-01-01T00:00:00.0000000Z",
"device_uuid": "pjleru42mvdhql4nl7mab6ympm",
"ip": "4.175.88.205"
}
}
user-delete: Change User State From
#Description
A user's state was changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "6G4SUOYYRTP6LBU2SZH6DP5QGU",
"timestamp": "1/8/2024, 6:40:52.312 PM",
"location": {
"country": "Portugal",
"region": "Faro",
"city": "Olh�o",
"latitude": 37.0272,
"longitude": -7.8338
},
"actor_uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
"actor_details": {
"uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
"name": "Tommy Shelby",
"email": "tommy.shelby@securehats.nl"
},
"action": "delete",
"object_type": "user",
"object_uuid": "SOI7VTRTWBEQHBZOS4U7J45SZA",
"object_details": {
"uuid": "SOI7VTRTWBEQHBZOS4U7J45SZA",
"name": "Roy Stoop",
"email": "roy@securehats.nl"
},
"session": {
"uuid": "X4FWG32AEJEMLDS5LWQZQC4QZQ",
"login_time": "2024-01-08T17:58:41.2889308Z",
"device_uuid": "wnxznnlchyi4cpqratg6dzigjq",
"ip": "95.93.92.51"
}
}
Detection Patterns #
Credential Access: Credentials from Password Stores
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
action (kusto rule field) | eq | delete | 1 rule | kusto |
action (kusto rule field) | eq | export | 1 rule | kusto |
object_type (kusto rule field) | eq | user | 1 rule | kusto |
object_type (kusto rule field) | eq | vault | 1 rule | kusto |
user-deolddev: Delete Old Devices
#Description
Old devices were deleted.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-disblmfa: Disable Multi-Factor Authentication
#Description
Multi-factor authentication was disabled.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "4WPGSI2CPDIDFTOIE2LD2SMXNP",
"timestamp": "1/3/2024, 2:42:28.196 PM",
"location": {
"country": "The Netherlands",
"region": "North Brabant",
"city": "Rijen",
"latitude": 51.5923,
"longitude": 4.9218
},
"actor_uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
"actor_details": {
"uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
"name": "Walter White",
"email": "walter.white@securehats.nl"
},
"action": "disblmfa",
"object_type": "user",
"object_uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
"object_details": {
"uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
"name": "Nigel Powers",
"email": "nigel.powers@securehats.nl"
},
"aux_id": "1487957",
"aux_info": "T",
"session": {
"uuid": "5NP22Y4FMJAMPO7ZYZMUO6GG6E",
"login_time": "2024-01-03T14:29:23.9986687Z",
"device_uuid": "uh7t35mrsnycrf4vz6wbdhs4y4",
"ip": "76.75.244.76"
}
}
user-enblmfa: Enable Multi-Factor Authentication
#Description
Multi-factor authentication was enabled.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "WIX2XBHSBIIBPCOWYUKIMJLIEZ",
"timestamp": "12/15/2023, 11:52:48.267 AM",
"location": {
"country": "The Netherlands",
"region": "North Holland",
"city": "Amsterdam",
"latitude": 52.3426,
"longitude": 4.8631
},
"actor_uuid": "54SFBG7JOJEQRKEY5TQ7JXRFVA",
"actor_details": {
"uuid": "54SFBG7JOJEQRKEY5TQ7JXRFVA",
"name": "Gus Fring",
"email": "gus.fring@securehats.nl"
},
"action": "enblmfa",
"object_type": "user",
"object_uuid": "54SFBG7JOJEQRKEY5TQ7JXRFVA",
"object_details": {
"uuid": "54SFBG7JOJEQRKEY5TQ7JXRFVA",
"name": "Gus Fring",
"email": "gus.fring@securehats.nl"
},
"aux_id": "1528119",
"aux_info": "T",
"session": {
"uuid": "2CONSQ6LFJDZVAMYLUHJFAEWEQ",
"login_time": "2023-12-15T11:52:48.2529735Z",
"device_uuid": "tew7ipdhu3jyrqa3llawqiqciy",
"ip": "178.132.215.44"
}
}
user-join: Change User State From
#Description
A user's state was changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-provsn: Provision (User)
#Description
1Password user event: Provision (User). This value appears in real 1Password telemetry but in neither the OpenAPI enum nor the documentation. A real record proves it exists; its meaning is undocumented and is deliberately not inferred here. Observed in real telemetry. The vendor docs carry no event row for this pairing.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "F5E2U2KRZ45FQX3OQLEQ7KKXPU",
"timestamp": "12/15/2023, 11:00:39.469 AM",
"location": {
"country": "The Netherlands",
"region": "North Holland",
"city": "Amsterdam",
"latitude": 52.3759,
"longitude": 4.8975
},
"actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"actor_details": {
"uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"name": "Automated User Provisioning",
"email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
},
"action": "provsn",
"object_type": "user",
"object_uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
"object_details": {
"uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
"name": "Arthur Shelby",
"email": "arthur.shelby@securehats.nl"
},
"session": {
"uuid": "TPEFXHZ62ZGTHCHMSNEMLLDPMA",
"login_time": "2023-12-14T11:39:44.9931456Z",
"device_uuid": "pjleru42mvdhql4nl7mab6ympm",
"ip": "4.175.88.205"
}
}
user-reactive: Change User State From
#Description
A user's state was changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "DUMMY-ID-0038",
"action": "reactive",
"session": {
"uuid": "DUMMY-ID-0039",
"login_time": "2026-07-23T14:45:23.491952496Z",
"device_uuid": "DUMMY-ID-0003",
"ip": "192.0.2.1"
},
"location": {
"country": "Dummy Country 001",
"region": "Dummy Region 001",
"city": "Dummy City 001",
"latitude": 0.0,
"longitude": 0.0
},
"timestamp": "2026-07-23T14:46:15.593777472Z",
"actor_type": "user",
"actor_uuid": "DUMMY-USER-0001",
"object_type": "user",
"object_uuid": "DUMMY-USER-0014",
"account_uuid": "DUMMY-ID-0004",
"actor_details": {
"uuid": "DUMMY-USER-0001",
"name": "Dummy User 001",
"email": "dummy.user001@example.invalid"
},
"object_details": {
"uuid": "DUMMY-USER-0014",
"name": "Dummy User 014",
"email": "dummy.user014@example.invalid"
}
}
user-resendts: Resend Provisioning Email
#Description
A provisioning email was resent.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "QRL3WULJSDSBSA5HKEFYWTVQRS",
"timestamp": "1/12/2024, 2:04:44.269 PM",
"location": {
"country": "The Netherlands",
"region": "North Brabant",
"city": "Rijen",
"latitude": 51.5923,
"longitude": 4.9218
},
"actor_uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
"actor_details": {
"uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
"name": "Walter White",
"email": "walter.white@securehats.nl"
},
"action": "resendts",
"object_type": "user",
"object_uuid": "HKIMSOYIIZGQJLKGOTZNZRRQQI",
"object_details": {
"uuid": "HKIMSOYIIZGQJLKGOTZNZRRQQI",
"name": "Felicity Shagwell",
"email": "felicity.sShagwell@securehats.nl"
},
"session": {
"uuid": "SYSZVH2JP5A75JDWJXWTUH3AGM",
"login_time": "2024-01-12T14:00:27.5697249Z",
"device_uuid": "uh7t35mrsnycrf4vz6wbdhs4y4",
"ip": "76.75.244.76"
}
}
user-sdvcsso: Set up Single Sign-On Authentication
#Description
A user set up their 1Password account to unlock with SSO.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-sendpkg: Send Package
#Description
A user sent an item to another user.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-sendts: Send Provisioning Email
#Description
A provisioning email was sent.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "HWZXV2CJDMOP4CUOJK2N545C6J",
"timestamp": "12/15/2023, 11:00:39.684 AM",
"location": {
"country": "The Netherlands",
"region": "North Holland",
"city": "Amsterdam",
"latitude": 52.3759,
"longitude": 4.8975
},
"actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"actor_details": {
"uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"name": "Automated User Provisioning",
"email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
},
"action": "sendts",
"object_type": "user",
"object_uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
"object_details": {
"uuid": "ZOMBFTD7YZA6ZKPY7SF22LGVQE",
"name": "Arthur Shelby",
"email": "arthur.shelby@securehats.nl"
},
"session": {
"uuid": "TPEFXHZ62ZGTHCHMSNEMLLDPMA",
"login_time": "2023-12-14T11:39:44.9931456Z",
"device_uuid": "pjleru42mvdhql4nl7mab6ympm",
"ip": "4.175.88.205"
}
}
user-suspend: Change User State From
#Description
A user's state was changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "N2W5JS4HXGXPEOR2RLKNOOC6GL",
"timestamp": "12/15/2023, 11:00:37.305 AM",
"location": {
"country": "The Netherlands",
"region": "North Holland",
"city": "Amsterdam",
"latitude": 52.3759,
"longitude": 4.8975
},
"actor_uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"actor_details": {
"uuid": "AVHAFAP4PRDF5K3724I67N3CEU",
"name": "Automated User Provisioning",
"email": "zkv4c3mauxjbw@1passwordserviceaccounts.com"
},
"action": "suspend",
"object_type": "user",
"object_uuid": "AONGS2F7BFFPNG2LBTFMRH562Q",
"object_details": {
"uuid": "AONGS2F7BFFPNG2LBTFMRH562Q",
"name": "Gideon Wories",
"email": "gideon.wories@securehats.nl"
},
"session": {
"uuid": "TPEFXHZ62ZGTHCHMSNEMLLDPMA",
"login_time": "2023-12-14T11:39:44.9931456Z",
"device_uuid": "pjleru42mvdhql4nl7mab6ympm",
"ip": "4.175.88.205"
}
}
Detection Patterns #
Credential Access: Credentials from Password Stores
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
action (kusto rule field) | eq | delete | 1 rule | kusto |
action (kusto rule field) | eq | export | 1 rule | kusto |
object_type (kusto rule field) | eq | user | 1 rule | kusto |
object_type (kusto rule field) | eq | vault | 1 rule | kusto |
user-tdvcsso: Enroll Trusted Device
#Description
A user set up a trusted device to unlock with SSO.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "DUMMY-ID-0005",
"action": "tdvcsso",
"session": {
"uuid": "DUMMY-ID-0006",
"login_time": "2026-08-08T05:24:35.851548919Z",
"device_uuid": "DUMMY-ID-0007",
"ip": "2001:db8::2"
},
"aux_uuid": "DUMMY-ID-0007",
"location": {
"country": "Dummy Country 002",
"region": "Dummy Region 002",
"city": "Dummy City 002",
"latitude": 0.0,
"longitude": 0.0
},
"timestamp": "2026-08-08T05:24:39.189355795Z",
"actor_type": "user",
"actor_uuid": "DUMMY-USER-0003",
"object_type": "user",
"object_uuid": "DUMMY-USER-0003",
"account_uuid": "DUMMY-ID-0004",
"actor_details": {
"uuid": "DUMMY-USER-0003",
"name": "Dummy User 003",
"email": "dummy.user003@example.invalid"
},
"object_details": {
"uuid": "DUMMY-USER-0003",
"name": "Dummy User 003",
"email": "dummy.user003@example.invalid"
}
}
user-trvlaway: Mark User Away For Travel
#Description
A user was marked as away for travel.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-trvlback: Mark User Back From Travel
#Description
A user was marked as back from travel.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-updatmfa: Update Multi-Factor Authentication
#Description
Multi-factor authentication was updated.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
Example Event #
{
"uuid": "TEJZL5OGDWBDXBIB622S2TR3FD",
"timestamp": "1/3/2024, 2:46:26.200 PM",
"location": {
"country": "South Africa",
"region": "Western Cape",
"city": "Cape Town",
"latitude": -33.91,
"longitude": 18.4304
},
"actor_uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
"actor_details": {
"uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
"name": "Nigel Powers",
"email": "nigel.powers@securehats.nl"
},
"action": "updatmfa",
"object_type": "user",
"object_uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
"object_details": {
"uuid": "Q3IELCBNUFAYXAECYF6FHCLXXQ",
"name": "Nigel Powers",
"email": "nigel.powers@securehats.nl"
},
"aux_id": "1487957",
"aux_info": "T",
"session": {
"uuid": "4PEKJD4YRBDNNEJ5QYHJ5XMECI",
"login_time": "2024-01-03T14:46:26.1592782Z",
"device_uuid": "wztcewt57uwnhze3ktqe2kkwyu",
"ip": "165.0.36.133"
}
}
user-upguest: Upgrade User
#Description
A guest was promoted to a family or team member.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |
user-verify: Change User State From
#Description
A user's state was changed.
Fields #
| Name | Description |
|---|---|
uuid | The unique identifier for the event. |
timestamp | When the action was performed. |
actor_uuid | The unique identifier for the team member who performed the action. |
actor_details.uuid | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_details.name | Full name |
actor_details.email | The details of the team member who performed the action (including their UUID, name, and email address). |
actor_type | |
actor_account_uuid | |
account_uuid | |
action | The type of action that was performed. |
object_type | The type of object that the action was performed on. |
object_uuid | The unique identifier for the object the action was performed on. |
object_details.uuid | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
object_details.name | Full name |
object_details.email | The details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member. |
aux_id | The identifier that relates to additional information about the activity. |
aux_uuid | The unique identifier that relates to additional information about the activity. |
aux_details.uuid | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_details.name | Full name |
aux_details.email | The details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member. |
aux_info | Additional information about the activity. |
session.uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.login_time | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.device_uuid | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
session.ip | The information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used. |
location.country | The geolocation information of the client based on their IP address at the time the event was performed. |
location.region | The geolocation information of the client based on their IP address at the time the event was performed. |
location.city | The geolocation information of the client based on their IP address at the time the event was performed. |
location.longitude | The geolocation information of the client based on their IP address at the time the event was performed. |
location.latitude | The geolocation information of the client based on their IP address at the time the event was performed. |