1Password - Secret extraction post vault access change by administrator

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This will alert when a secret extraction has occurred after an administrator has changed their own vault access permissions within that same vault. Ref: https://1password.com/ Ref: https://github.com/securehats/

Attribute Value
Type Analytic Rule
Solution 1Password
ID 6711b747-16d7-4df4-9f61-8633617f45d7
Severity High
Kind Scheduled
Tactics CredentialAccess
Techniques T1555
Required Connectors 1Password
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
OnePasswordEventLogs_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to 1Password