
Summary
The 'Wiz Update IP Restrictions' rule is designed to detect any modifications to IP restrictions within the Wix platform, specifically aimed at managing access via IP allowlisting. The rule provides a structured method to track updates effectively, ensuring that any unauthorized or unintended changes can be promptly identified and mitigated. When an update occurs, the system logs specific details including the user, IP addresses modified, and other parameters related to the action. It has a high severity level due to the potential impact of incorrect IP allowlisting on security. Proper validation procedures are enforced via a runbook that stresses the importance of confirming whether the changes were anticipated and documented, thereby enforcing policy adherence and accountability.
Categories
- Cloud
- Web
- Identity Management
Data Sources
- WMI
- Logon Session
- Application Log
ATT&CK Techniques
- T1556.009
Created: 2024-09-16