We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Detects when a user logs into a newly seen country over the last 30d, which could potentially indicate account compromise.
Ref internal: 540bc789-be24-4dbc-970c-a16489661290
540bc789-be24-4dbc-970c-a16489661290
other
New Terms
No response
logs-slack.audit
event.action:user_login and source.ip:* and user.email:* and source.geo.country_iso_code:*
user.email
source.geo.country_iso_code
https://api.slack.com/admins/audit-logs-call
The text was updated successfully, but these errors were encountered:
brokensound77
No branches or pull requests
Description
Detects when a user logs into a newly seen country over the last 30d, which could potentially indicate account compromise.
Ref internal:
540bc789-be24-4dbc-970c-a16489661290
Target Ruleset
other
Target Rule Type
New Terms
Tested ECS Version
No response
Query
logs-slack.audit
user.email
,source.geo.country_iso_code
New fields required in ECS/data sources for this rule?
No response
Related issues or PRs
No response
References
https://api.slack.com/admins/audit-logs-call
Redacted Example Data
No response
The text was updated successfully, but these errors were encountered: