1Password-Vault

EventTitleChannelSampleRule
anyVault (catch-all)_catch_allNN
vault-createAdd Vaultvault-createNN
vault-deleteDelete Vaultvault-deleteYY
vault-exportExport Vaultvault-exportYY
vault-purgeMark Vault To Be Purgedvault-purgeNN
vault-updateUpdate Client Accessvault-updateNN
vault-updateaUpdate Attributesvault-updateaYN

any: Vault (catch-all)

#

Description

Catch-all entry for 1Password rules that match vault events without naming a specific action.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

vault-create: Add Vault

#

Description

A vault was added.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

vault-delete: Delete Vault

#

Description

A vault was deleted.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

Example Event #

{
  "uuid": "UVXT6YVDXMQMGVSPIT3LNLOMQ2",
  "timestamp": "1/22/2024, 9:16:15.595 PM",
  "location": {
    "country": "The Netherlands",
    "region": "North Brabant",
    "city": "Rijen",
    "latitude": 51.5923,
    "longitude": 4.9218
  },
  "actor_uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
  "actor_details": {
    "uuid": "QD3Q2WVSVZFHZMC3O6HY3VSC6Y",
    "name": "Walter White",
    "email": "walter.white@securehats.nl"
  },
  "action": "delete",
  "object_type": "vault",
  "object_uuid": "fpl6uwaz6aazj2ly56jlxjcomi",
  "session": {
    "uuid": "NTB4XSFZFZBFNNCYGEK6JWQYSI",
    "login_time": "2024-01-22T21:12:57.7107500Z",
    "device_uuid": "uh7t35mrsnycrf4vz6wbdhs4y4",
    "ip": "76.75.244.76"
  }
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
action (kusto rule field)eqdelete1 rulekusto
action (kusto rule field)eqexport1 rulekusto
object_type (kusto rule field)equser1 rulekusto
object_type (kusto rule field)eqvault1 rulekusto

vault-export: Export Vault

#

Description

A vault was exported.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

Example Event #

{
  "uuid": "FBODO62J4WR72EGECMVQ5BCAF4",
  "timestamp": "1/15/2024, 10:57:31.218 AM",
  "location": {
    "country": "The Netherlands",
    "region": "Utrecht",
    "city": "Amersfoort",
    "latitude": 52.1849,
    "longitude": 5.3954
  },
  "actor_uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
  "actor_details": {
    "uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
    "name": "Tommy Shelby",
    "email": "tommy.shelby@securehats.nl"
  },
  "action": "export",
  "object_type": "vault",
  "object_uuid": "n36hcpeonwo63gr566l5kqww7u",
  "session": {
    "uuid": "HDG7CELQ6NBTBNY6W362BZAT2E",
    "login_time": "2024-01-15T10:56:59.3311720Z",
    "device_uuid": "se3mwxcxoyttdxigu3rgwn3d6i",
    "ip": "80.114.2.247"
  }
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
action (kusto rule field)eqexport3 ruleskusto
action (kusto rule field)eqdelete1 rulekusto
object_type (kusto rule field)eqvault3 ruleskusto
object_type (kusto rule field)equser1 rulekusto

vault-purge: Mark Vault To Be Purged

#

Description

A vault was marked for purging.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

vault-update: Update Client Access

#

Description

The client access value for a vault was updated.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

vault-updatea: Update Attributes

#

Description

A vault name or description was changed.

Fields #

NameDescription
uuidThe unique identifier for the event.
timestampWhen the action was performed.
actor_uuidThe unique identifier for the team member who performed the action.
actor_details.uuidThe details of the team member who performed the action (including their UUID, name, and email address).
actor_details.nameFull name
actor_details.emailThe details of the team member who performed the action (including their UUID, name, and email address).
actor_type
actor_account_uuid
account_uuid
actionThe type of action that was performed.
object_typeThe type of object that the action was performed on.
object_uuidThe unique identifier for the object the action was performed on.
object_details.uuidThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
object_details.nameFull name
object_details.emailThe details of the team member who is the object of the action (including their UUID, name, and email address). This property is only returned for events where the object of the action is a team member.
aux_idThe identifier that relates to additional information about the activity.
aux_uuidThe unique identifier that relates to additional information about the activity.
aux_details.uuidThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_details.nameFull name
aux_details.emailThe details of the team member who relates to the additional information about the activity (including their UUID, name, and email address). This property is only returned for events where the additional information about an activity relates to a team member.
aux_infoAdditional information about the activity.
session.uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.login_timeThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.device_uuidThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
session.ipThe information about the session, including the date and time the client signed in and started the session, the unique identifier of the device that signed into the session, and the IP address used.
location.countryThe geolocation information of the client based on their IP address at the time the event was performed.
location.regionThe geolocation information of the client based on their IP address at the time the event was performed.
location.cityThe geolocation information of the client based on their IP address at the time the event was performed.
location.longitudeThe geolocation information of the client based on their IP address at the time the event was performed.
location.latitudeThe geolocation information of the client based on their IP address at the time the event was performed.

Example Event #

{
  "uuid": "DRH5ZT5EQDVJ4EQFYKMNH2ADSL",
  "timestamp": "1/15/2024, 10:54:32.610 AM",
  "location": {
    "country": "The Netherlands",
    "region": "Utrecht",
    "city": "Amersfoort",
    "latitude": 52.1849,
    "longitude": 5.3954
  },
  "actor_uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
  "actor_details": {
    "uuid": "2C4RSXPRI5BVFOS3TCJFYDZYXY",
    "name": "Tommy Shelby",
    "email": "tommy.shelby@securehats.nl"
  },
  "action": "updatea",
  "object_type": "vault",
  "object_uuid": "n36hcpeonwo63gr566l5kqww7u",
  "session": {
    "uuid": "4YN2SFKZJ5E5RJGIB5LRFNNFZM",
    "login_time": "2024-01-15T10:46:49.2290152Z",
    "device_uuid": "tmikosahabjierhqhaapybduj4",
    "ip": "80.114.2.247"
  }
}

References #