heroui logo

Auth0 Bot Detection Policy Disabled

Panther Rules

View Source
Summary
The rule titled 'Auth0 Bot Detection Policy Disabled' is designed to monitor the status of the bot detection feature within Auth0. This rule is critical for organizations relying on Auth0 for authentication and user management as it helps in identifying any disabling actions associated with bot detection policies. When such a policy is disabled, it presents potential vulnerabilities since it could allow automated bots to exploit the service, leading to various cyber threats including account takeovers and service abuse. The rule is triggered when logs indicate that the bot detection feature has been turned off, alerting security administrators to investigate the change. Enforcement requires that this setting be re-evaluated for necessity and reinstated for optimal security posture. The rule includes a test mechanism that will check the enablement status and log details of relevant API requests, ensuring a comprehensive assessment of user actions pertaining to the rule.
Categories
  • Identity Management
  • Cloud
  • Application
Data Sources
  • Application Log
  • User Account
ATT&CK Techniques
  • T1562
Created: 2025-10-17