NordPass
Telemetry Evidence
These values show how indexed rules identify NordPass telemetry.Kusto
NordPassEventLogs_CL
Detection Rules
Kusto #
- NordPass - Activity token revocation source medium: This will alert you when the event reporting token is revoked, posing the risk of active integration being blocked.
T1134 - NordPass - Declined invitation source low: This will alert you when the user declines the invite to the NordPass organization.
T1078 - NordPass - Deleting items of deleted member source high: This will alert you if the deleted user's items have been removed without being transferred to another active user, as this could result in the loss of access to critical tools or information.
T1485 - NordPass - Domain data detected in breach source high: This will alert you when Data Breach Scanner discovers data related to your organization's domains on the dark web. !This rule should be enabled only by the organizations that have set up Data Breach Scanner in NordPass.
T1020 - NordPass - Manual invitation, suspension, or deletion source medium: This will alert you when the user is manually invited, suspended, or deleted. !This rule should be enabled only by organizations that have User and Group Provisioning enabled.
T1098 - NordPass - User data detected in breach source high: This will alert you when Data Breach Scanner discovers data related to a member of your organization on the dark web.
T1020 - NordPass - User deletes items in bulk source high: This will alert you if a user deletes items in bulk, namely, more than 10 items or in the span of 10 minutes. If a mix of bulk and one-off deletions were performed, this will group all actions and report the total number of items deleted.
T1074,T1485 - NordPass - User fails authentication source high: This will alert you if a user fails to log in to their NordPass account or SSO authentication three or more times in the last 24 hours.
T1110,T1556,T1556.003 - NordPass - Vault export source high: This will alert you if the vault has been exported, allowing you to review and evaluate the incident to mitigate potential risks. NOTE: The organization can control whether it allows its members to export the vault, although we recommend that it always be disabled.
T1020