1Password - Potential insider privilege escalation via vault

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This will alert when an actor grants, or updates their own permissions via a vault. Once this analytics rule is triggered it will group all related future alerts for upto an hour when all related entities are the same. Ref: https://1password.com/ Ref: https://github.com/securehats/

Attribute Value
Type Analytic Rule
Solution 1Password
ID a00ffbd8-1d1c-47a3-b0a6-7d70bd8017ed
Severity Medium
Kind Scheduled
Tactics PrivilegeEscalation
Techniques T1078
Required Connectors 1Password
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
OnePasswordEventLogs_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to 1Password