heroui logo

Wiz Update Login Settings

Panther Rules

View Source
Summary
The 'Wiz Update Login Settings' detection rule is designed to monitor updates to the login settings of Wiz accounts. It has a medium severity level and activates upon any changes made to the approved user domains for login access. The rule uses the Wiz Audit logs as its primary data source and checks for successful and unsuccessful update attempts. If an unauthorized change is detected, it suggests verifying the change against planned security policies and reverting any unexpected modifications. Additionally, the rule ensures that updates conform to expected results by executing test scenarios for normal and erroneous cases, making it robust in identifying discrepancies. Documentation and support for managing user accounts within the Wiz platform can be accessed via an external URL for further guidance on best practices.
Categories
  • Cloud
  • Identity Management
Data Sources
  • WMI
  • Application Log
  • User Account
ATT&CK Techniques
  • T1556
Created: 2024-09-16