
Summary
This detection rule identifies when a user publishes a page on Notion to the web, which could lead to potential information exposure. The rule is set to trigger whenever such an action occurs, capturing one instance and deduplicating subsequent alerts for 60 minutes to reduce noise. With a low severity rating, it acts as a precautionary measure to inform administrators of possible information disclosure scenarios. The rule relies on audit logs generated by the Notion environment to provide actionable insights. It is advisable for organizations to review published pages and take corrective action as necessary to protect sensitive information.
Categories
- Cloud
- Web
- Application
Data Sources
- User Account
- Application Log
Created: 2023-10-13