
Summary
The detection rule 'Zendesk Credit Card Redaction Off' monitors account settings in Zendesk for unauthorized changes regarding credit card data protection. When a user disables credit card redaction, which is critical for safeguarding sensitive financial information, this event triggers an alert due to the potential security risk it represents. The rule captures successful updates made to the account setting that specifically alters the credit card redaction feature, indicating that such sensitive data may no longer be automatically obscured in tickets, exposing the organization to compliance issues and potential breaches. Severely rated as 'High', it ensures that such configurations are closely monitored, and the rule suggests reverting the action to re-enable redaction if detected. The implementation of this rule provides a critical layer of oversight to data handling practices within Zendesk, helping organizations maintain compliance with data privacy regulations.
Categories
- Cloud
- Application
Data Sources
- User Account
- Application Log
- Logon Session
ATT&CK Techniques
- T1213
Created: 2022-09-02