heroui logo

Notion Many Pages Deleted [Deprecated]

Panther Rules

View Source
Summary
The rule 'Notion Many Pages Deleted' is designed to detect and raise flags when a Notion user deletes multiple pages in rapid succession, indicating potential unauthorized data destruction activities. This is particularly relevant for organizations reliant on Notion for storing critical information, as sudden mass deletions can signal that either malicious actors are at work or that an internal process has gone awry. The rule was set with a threshold of 10 deletions within a one-hour period and was designed to alert security teams to take follow-up action with the involved user. However, the rule has been deprecated primarily due to its tendency to generate false positives, leading to unnecessary investigations and potential notifications about normal user behavior. It is crucial that this detection mechanism is used judiciously, particularly given the potential for chaotic data management in collaborative environments like Notion.
Categories
  • Cloud
  • Application
Data Sources
  • User Account
  • Application Log
  • Service
Created: 2023-06-14