heroui logo

Signal - Notion Account Changed

Panther Rules

View Source
Summary
The detection rule 'Notion.AccountChange' is designed to monitor changes in user account information within Notion. This rule specifically tracks events related to user account settings alterations, such as email updates. It utilizes Notion's audit logs as its primary data source to identify and log changes. The rule is set at an 'Info' severity level, indicating that while the changes are noteworthy, they do not represent immediate threats. The rule is triggered if at least one relevant event is detected within a 60-minute deduplication period and focuses on events where user account settings have been modified. It operates under the assumption that a user action, such as updating their email address, may indicate a benign change in account settings but should be logged for auditing purposes. The rule does not generate alerts, which suggests it may be intended for internal logging or monitoring without alarming security personnel unless unusual patterns are detected.
Categories
  • Identity Management
  • Web
Data Sources
  • User Account
  • Logon Session
  • Application Log
Created: 2024-09-16