
Summary
The detection rule 'Auth0 New Admin Invited' is designed to monitor for new admin invitations issued through the Auth0 platform. When a new admin invitation is created, the rule captures relevant event logs from Auth0. The process is initiated when an administrator specifies an email and assigns roles to the new user. Successful executions of these invitations are logged, with specific user details, timestamps, and client information. The rule aims to track normal administrative actions and help mitigate potential risks by reporting unusual patterns or discrepancies during the invitation process. Although the severity is marked as 'Info' and alerts are not created automatically, this information could be beneficial in auditing admin activities and preventing unauthorized access or tenant takeover scenarios.
Categories
- Identity Management
- Cloud
- Web
- Application
Data Sources
- Web Credential
- User Account
- Application Log
ATT&CK Techniques
- T1136
Created: 2025-10-29