Skip to content

Latest commit

 

History

History
31 lines (24 loc) · 823 Bytes

MATCH-S00848.md

File metadata and controls

31 lines (24 loc) · 823 Bytes

Rules: LastPass - Password Changed

Description

Detects passwordchanged events from LastPass

Additional Details

Detail Value
Type Templated Match
Category Persistence
Apply Risk to Entities user_username, srcDevice_ip
Signal Name LastPass password changed for user: {{user_username}}
Summary Expression LastPass password changed for user: {{user_username}} from source IP: {{srcDevice_ip}}
Score/Severity Static: 1
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0003, _mitreAttackTechnique:T1098

Vendors and Products

Fields Used

Origin Field
Normalized Schema metadata_deviceEventId
Normalized Schema metadata_product
Normalized Schema metadata_vendor
Normalized Schema srcDevice_ip
Normalized Schema user_username