OneLogin
Telemetry Evidence
These values show how indexed rules identify OneLogin telemetry.Panther
OneLogin.Events onelogin Sigma
onelogin onelogin.events YARA-L
OneLogin ONELOGIN_SSO ONELOGIN
Detection Rules
Panther #
- Admin Role Assigned source medium: Assigning an admin role manually could be a sign of privilege escalation
T1078 - Brute Force By IP source informational: An actor user was denied login access more times than the configured threshold.
T1110 - Brute Force By User source informational: An actor user was denied login access more times than the configured threshold.
T1110 - GreyNoise V3 Malicious IP Activity source high: Detects when an IP address in any log event is classified as malicious or unknown by GreyNoise V3 internet scanner intelligence. Known business services and benign IPs are excluded.
T1595.001 - GTI/VirusTotal Threat Intelligence Indicator Match source high: Detects when an IP address, domain, or file hash in any log event matches a known malicious indicator from Google Threat Intelligence (GTI) / VirusTotal enrichment. Severity is elevated based on GTI's threat severity verdict and the number of vendors flagging the indicator as malicious.
T1595.001 - New User Account Created source informational: A new account was created
T1136 - OneLogin Active Login Activity source medium: Multiple user accounts logged in from the same ip address.
T1550 - OneLogin Authentication Factor Removed source low: A user removed an authentication factor or otp device.
T1556 - OneLogin Failed High Risk Login source low: A OneLogin attempt with a high risk factor (>50) resulted in a failed authentication.
- OneLogin Multiple Accounts Deleted source medium: Possible Denial of Service detected. Threshold for user account deletions exceeded.
T1531
Show 9 more
- OneLogin Multiple Accounts Modified source medium: Possible Denial of Service detected. Threshold for user account password changes exceeded.
T1531 - OneLogin Password Access source medium: User accessed another user's application password
T1552 - OneLogin Unauthorized Access source medium: A OneLogin user was denied access to an app more times than the configured threshold.
T1550 - OneLogin User Assumed Another User source low: User assumed another user account
T1550 - OneLogin User Locked source low: User locked or suspended from their account.
T1110 - OneLogin User Password Changed source informational: A user password was updated.
- OTX Threat Intelligence Indicator Match source high: Detects when an IP address in any log event matches a known threat indicator from AlienVault OTX pulse intelligence. Severity is elevated when the pulse includes a named adversary or known malware families.
T1595.001 - Sign In from Rogue State source medium: Detects when an entity signs in from a nation associated with cyber attacks
T1078.004 - Signal - OneLogin Login source informational: A OneLogin user successfully logged in.
Sigma #
- OneLogin User Account Locked source low: Detects when an user account is locked or suspended.
- OneLogin User Assumed Another User source low: Detects when an user assumed another user account.
YARA-L #
- OneLogin Application Password Revealed source high: Detects when a user revealed another user's application password.
T1552 - OneLogin Multiple Users Assumed source low: Detects when a user assumes multiple user accounts.
T1550 - OneLogin Multiple Users Login Failures From The Same IP source medium: Detects multiple users login failures from a single IP.
T1078,T1078.004 - OneLogin OTP Bruteforce Attack source high: Detects a successful login after multiple failed OTP intents
T1110 - OneLogin Super User Privileges Assigned source high: Detects when a user is assigned super user privileges.
T1078,T1078.004 - OneLogin User Authentication Factor Removed source high: Detects when a user removes an authentication factor or otp device.
T1556,T1556.006 - OneLogin User Logins From Multiple Countries source medium: Detects user logins for the same user from different cities within 24 hours.
T1078,T1078.004