heroui logo

Auth0 Delete Tenant Member

Panther Rules

View Source
Summary
The rule 'Auth0 Delete Tenant Member' is designed to monitor and log events related to the deletion of tenant members within an Auth0 environment. This detection focuses specifically on events that signify when a member is removed from a tenant. The primary functionality involves capturing events logged in the 'Auth0.Events' source, with the goal of ensuring security by monitoring potentially risky operations that can lead to unauthorized tenant takeovers. The severity of the alerts generated by this rule is categorized as 'Info', and thus it does not trigger significant alerts but serves to inform administrators about the activity. In the provided example test cases, the rule expects to log a deletion event while disregarding unrelated activities such as creating tenant invitations. This proactive logging function enables better awareness and audit trails in environments utilizing Auth0 for user management.
Categories
  • Cloud
  • Application
  • Identity Management
Data Sources
  • User Account
  • Application Log
ATT&CK Techniques
  • T1041
Created: 2025-10-29