Asana
Telemetry Evidence
These values show how indexed rules identify Asana telemetry.Panther
Asana.Audit asana
Detection Rules
Panther #
- Admin Role Assigned source medium: Assigning an admin role manually could be a sign of privilege escalation
T1078 - Asana Service Account Created source medium: An Asana service account was created by someone in your organization.
- Asana Team Privacy Public source low: An Asana team's privacy setting was changed to public to the organization (not public to internet)
- Asana Workspace Default Session Duration Never source low: An Asana workspace's default session duration (how often users need to re-authenticate) has been changed to never.
- Asana Workspace Email Domain Added source low: A new email domain has been added to an Asana workspace. Reviewer should validate that the new domain is a part of the organization.
- Asana Workspace Form Link Auth Requirement Disabled source low: An Asana Workspace Form Link is a unique URL that allows you to create a task directly within a specific Workspace or Project in Asana, using a web form. Disabling authentication requirements may allow unauthorized users to create tasks.
- Asana Workspace Guest Invite Permissions Anyone source low: Typically inviting guests to Asana is permitted by few users. Enabling anyone to invite guests can potentially lead to unauthorized users gaining access to Asana.
- Asana Workspace New Admin source high: Admin role was granted to the user who previously did not have admin permissions
- Asana Workspace Org Export source medium: An Asana user started an org export.
- Asana Workspace Password Requirements Simple source medium: An asana user made your organization's password requirements less strict.
Show 9 more
- Asana Workspace Require App Approvals Disabled source medium: An Asana user turned off app approval requirements for an application type for your organization.
- Asana Workspace SAML Optional source medium: An Asana user made SAML optional for your organization.
- Brute Force By IP source informational: An actor user was denied login access more times than the configured threshold.
T1110 - Brute Force By User source informational: An actor user was denied login access more times than the configured threshold.
T1110 - GreyNoise V3 Malicious IP Activity source high: Detects when an IP address in any log event is classified as malicious or unknown by GreyNoise V3 internet scanner intelligence. Known business services and benign IPs are excluded.
T1595.001 - GTI/VirusTotal Threat Intelligence Indicator Match source high: Detects when an IP address, domain, or file hash in any log event matches a known malicious indicator from Google Threat Intelligence (GTI) / VirusTotal enrichment. Severity is elevated based on GTI's threat severity verdict and the number of vendors flagging the indicator as malicious.
T1595.001 - Impossible Travel for Login Action source high: A user has subsequent logins from two geographic locations that are very far apart
T1078 - OTX Threat Intelligence Indicator Match source high: Detects when an IP address in any log event matches a known threat indicator from AlienVault OTX pulse intelligence. Severity is elevated when the pulse includes a named adversary or known malware families.
T1595.001 - Sign In from Rogue State source medium: Detects when an entity signs in from a nation associated with cyber attacks
T1078.004