heroui logo

Zendesk User Suspension Status Changed

Panther Rules

View Source
Summary
The "Zendesk User Suspension Status Changed" rule is designed to monitor changes to user suspension statuses within the Zendesk platform. This rule will trigger when a user's suspension is either initiated or lifted, ensuring that appropriate actions are taken in cases of account access modification. It primarily watches for actions captured in the Zendesk audit logs, indicating whether a user has been suspended or unsuspended by an administrator. The significance of this rule stems from its ability to manage user access effectively, ensuring that only authorized personnel have their account status altered. Logging is key to maintain an audit trail for any modifications made. The rule asserts a high severity level due to the potential risks associated with account access and management by unauthorized individuals. The provided tests confirm that the rule checks for updates and ensures that inappropriate user access is curtailed swiftly and effectively. Immediate investigation and corrective actions may be required in cases of unauthorized role changes, as indicated by the related log entries.
Categories
  • Cloud
  • Identity Management
Data Sources
  • User Account
  • Application Log
ATT&CK Techniques
  • T1531
Created: 2022-09-02