
Summary
The detection rule titled "Configuration Required - Sensitive 1Password Item Accessed" is designed to monitor and alert when a user accesses sensitive items in 1Password. Specifically, this rule checks for user interactions with a predefined list of sensitive items stored within the 1Password vault. When such an access event is detected through log entries classified as "OnePassword.ItemUsage", the rule evaluates the entry against specified criteria to determine whether the access is appropriate or anomalous. The rule is intended to uncover potential unauthorized access to sensitive credentials, which could signify a risk of data breach or credential exposure. It generates alerts with a low severity level, suggesting that while the potential threat exists, it may not require immediate action. The rule is currently disabled and relies on the log types from 1Password, primarily focused on usage scenarios involving sensitive data.
Categories
- Identity Management
- Cloud
- Application
Data Sources
- User Account
- Application Log
ATT&CK Techniques
- T1552
Created: 2022-09-02