Notion
Telemetry Evidence
These values show how indexed rules identify Notion telemetry.Panther
Notion.AuditLogs notion panther_logs.public.notion_auditlogs
Detection Rules
Panther #
- GreyNoise V3 Malicious IP Activity source high: Detects when an IP address in any log event is classified as malicious or unknown by GreyNoise V3 internet scanner intelligence. Known business services and benign IPs are excluded.
T1595.001 - GTI/VirusTotal Threat Intelligence Indicator Match source high: Detects when an IP address, domain, or file hash in any log event matches a known malicious indicator from Google Threat Intelligence (GTI) / VirusTotal enrichment. Severity is elevated based on GTI's threat severity verdict and the number of vendors flagging the indicator as malicious.
T1595.001 - Impossible Travel for Login Action source high: A user has subsequent logins from two geographic locations that are very far apart
T1078 - Notion Audit Log Exported source medium: A Notion User exported audit logs for your organization’s workspace.
- Notion Login From Blocked IP source medium: A user attempted to access Notion from a blocked IP address. Note: before deployinh, make sure to add Rule Filters checking if event.ip_address is in a certain CIDR range(s).
- Notion Login from New Location source medium: A Notion User logged in from a new location.
- Notion Many Pages Deleted [Deprecated] source medium: (Deprecated due to false-positive rate) A Notion User deleted multiple pages.
- Notion Many Pages Deleted Query source: A Notion User deleted multiple pages, which were not created or restored from the trash within the same hour.
- Notion Many Pages Exported source high: A Notion User exported multiple pages.
- Notion Page API Permissions Changed source low: A new API integration was added to a Notion page, or it's permissions were changed.
Show 12 more
- Notion Page Guest Permissions Changed source low: The external guest permissions for a Notion page have been altered.
- Notion Page Published to Web source low: A Notion User published a page to the web.
- Notion SAML SSO Configuration Changed source high: A Notion User changed settings to enforce SAML SSO configurations for your organization.
- Notion SCIM Token Generated source medium: A Notion User generated a SCIM token.
- Notion Sharing Settings Updated source medium: A Notion User enabled sharing for a Workspace or Teamspace.
- Notion Teamspace Owner Added source medium: A Notion User was added as a Teamspace owner.
- Notion Workspace Exported source high: A Notion User exported an existing workspace.
- Notion Workspace public page added source informational: A Notion page was set to public in your worksace.
- OTX Threat Intelligence Indicator Match source high: Detects when an IP address in any log event matches a known threat indicator from AlienVault OTX pulse intelligence. Severity is elevated when the pulse includes a named adversary or known malware families.
T1595.001 - Sign In from Rogue State source medium: Detects when an entity signs in from a nation associated with cyber attacks
T1078.004 - Signal - Notion Account Changed source informational: A Notion User changed their account information.
- Signal - Notion Login source informational: A Notion User logged in.
Package-Only Rules
These rules appear in a Notion source package, but their queries do not identify Notion telemetry. They do not count toward Rules.Panther #