Detection rules › Splunk

Zoom Rare Input Devices

Status
experimental
Author
Marissa Bower, Raven Tait
Source
github.com/splunk/security_content

Detects rare input devices from Zoom logs. Actors performing Remote Employment Fraud (REF) typically use unusual device information compared to a majority of employees. Detecting this activity requires careful analysis, regular review, and a thorough understanding of the audio and video devices commonly used within your environment.

MITRE ATT&CK coverage

TacticTechniques
CollectionT1123 Audio Capture

Rule body splunk

name: Zoom Rare Input Devices
id: d290eeef-d05e-49a8-b598-72296023b87b
version: 3
creation_date: '2025-06-12'
modification_date: '2026-05-13'
author: Marissa Bower, Raven Tait
status: experimental
type: Hunting
description: Detects rare input devices from Zoom logs. Actors performing Remote Employment Fraud (REF) typically use unusual device information compared to a majority of employees. Detecting this activity requires careful analysis, regular review, and a thorough understanding of the audio and video devices commonly used within your environment.
data_source: []
search: |-
    `zoom_index` microphone=* NOT (camera=*iPhone* OR camera="*FaceTime*" OR speaker="*AirPods*" OR camera="*MacBook*" OR microphone="*MacBook Pro Microphone*")
      | rare microphone limit=50
      | `zoom_rare_input_devices_filter`
how_to_implement: The analytic leverages Zoom logs to be ingested using Splunk Connect for Zoom (https://splunkbase.splunk.com/app/4961)
known_false_positives: This is a hunting query meant to identify rare microphone devices.
analytic_story:
    - Remote Employment Fraud
asset_type: Identity
mitre_attack_id:
    - T1123
product:
    - Splunk Enterprise
    - Splunk Enterprise Security
    - Splunk Cloud
category: application
security_domain: identity

Stages and Predicates

Stage 1: search

`zoom_index` microphone=* NOT (camera=*iPhone* OR camera="*FaceTime*" OR speaker="*AirPods*" OR camera="*MacBook*" OR microphone="*MacBook Pro Microphone*")

Stage 2: rare

| rare microphone limit=50

Stage 3: search

| `zoom_rare_input_devices_filter`

Exclusions

Top-level NOT(...) conjuncts: predicates this rule actively suppresses.

FieldKindExcluded values
cameraeq*iPhone*
cameraeq"*FaceTime*"
cameraeq"*MacBook*"
microphoneeq"*MacBook Pro Microphone*"
speakereq"*AirPods*"

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
microphoneeq
  • *