heroui logo

Snyk Miscellaneous Settings

Panther Rules

View Source
Summary
The 'Snyk Miscellaneous Settings' detection rule monitors changes to Snyk settings that do not have a clear security impact. The rule is enabled and set to log changes from both 'Snyk.GroupAudit' and 'Snyk.OrgAudit' logs. It operates with a low severity threshold, capturing events regarding adjustments in feature flags or user permissions within the Snyk environment. Key detection features of this rule include immediate flagging of changes, with a deduplication period of 60 minutes to avoid repeated alerts for similar actions. If a feature flag change is recorded as 'true' but a user invite revoke logs as 'false', the rule highlights potentially unauthorized access or configuration changes that may not enhance security practices. This monitoring focuses not only on compliance but also on operational integrity within Snyk's configuration management.
Categories
  • Cloud
  • Application
Data Sources
  • User Account
  • Application Log
Created: 2023-04-26