LastPass
Telemetry Evidence
These values show how indexed rules identify LastPass telemetry.Kusto
LastPassNativePoller_CL
Detection Rules
Kusto #
- Employee account deleted source medium: 'This rule will monitor for any employee accounts being deleted. Deleting an employee account can have a big potential impact as all of the data for that user will be removed.'
T1485 - Failed sign-ins into LastPass due to MFA source low: This rule will check if a sign-in failed into LastPass due to MFA. An incident can indicate the potential brute forcing of a LastPass account. The use of MFA is identified by combining the sign-in logs, this rule assumes LastPass is federated to Entra ID.
T1078,T1190 - Highly Sensitive Password Accessed source medium: 'This rule will monitor access to highly sensitive passwords. Within the Watchlist called 'LastPass' define passwords which are deemed highly sensitive (such as password to a high privileged application). When an activity is observed against such password, an incident is created.'
T1087,T1555 - TI map IP entity to LastPass data source medium: 'Identifies a match in LastPass table from any IP IOC from TI'
T1485 - Unusual Volume of Password Updated or Removed source low: 'This rule will check if there is an unnormal activity of sites that are deleted or changed per user. The normal amount of actions is calculated based on the previous 14 days of activity. If there is a significant increase, an incident will be created.'
T1485