Ping
Telemetry Evidence
These values show how indexed rules identify Ping telemetry.Kusto
PingFederateEvent Splunk
PingID
Detection Rules
Kusto #
- Ping Federate - Abnormal password reset attempts source high: 'Detects abnormal password reset attempts for user in short period of time.'
T1110 - Ping Federate - Abnormal password resets for user source high: 'Detects multiple password reset for user.'
T1078,T1098,T1134 - Ping Federate - Authentication from new IP. source low: 'Detects authentication requests from new IP address.'
T1078 - Ping Federate - Forbidden country source high: 'Detects requests from forbidden countries.'
T1078 - Ping Federate - New user SSO success login source low: 'Detects new user SSO success login.'
T1078,T1136 - Ping Federate - OAuth old version source medium: 'Detects requests using not the latest version of OAuth protocol.'
T1190 - Ping Federate - Password reset request from unexpected source IP address.. source medium: 'Detects password reset requests from unexpected source IP address.'
T1078 - Ping Federate - SAML old version source medium: 'Detects requests using not the latest version of SAML protocol.'
T1190 - Ping Federate - Unexpected authentication URL. source medium: 'Detects unexpected authentication URL.'
T1078 - Ping Federate - Unexpected country for user source medium: 'Detects requests from different countries for user in shotr term.'
T1078
Show 1 more
- Ping Federate - Unusual mail domain. source medium: 'Detects unusual mail domain in authentication requests.'
T1078
Splunk #
- PingID Mismatch Auth Source and Verification Response source medium: The following analytic identifies discrepancies between the IP address of an authentication event and the IP address of the verification response event, focusing on differences in the originating countries. It leverages JSON logs from PingID, comparing the 'auth_Country' and 'verify_Country' fields. This activity is significant as it may indicate suspicious sign-in behavior, such as account compromise or unauthorized access attempts. If confirmed malicious, this could allow attackers to bypass authentication mechanisms, potentially leading to unauthorized access to sensitive systems and data.
T1098,T1098.005,T1556,T1556.006,T1621 - PingID Multiple Failed MFA Requests For User source medium: The following analytic identifies multiple failed multi-factor authentication (MFA) requests for a single user within a PingID environment. It triggers when 10 or more MFA prompts fail within 10 minutes, using JSON logs from PingID. This activity is significant as it may indicate an adversary attempting to bypass MFA by bombarding the user with repeated authentication requests. If confirmed malicious, this could lead to unauthorized access, as the user might eventually accept the fraudulent request, compromising the security of the account and potentially the entire network.
T1078,T1110,T1621 - PingID New MFA Method After Credential Reset source
T1098,T1098.005,T1556,T1556.006,T1621 - PingID New MFA Method Registered For User source medium: The following analytic detects the registration of a new Multi-Factor Authentication (MFA) method for a PingID (PingOne) account. It leverages JSON logs from PingID, specifically looking for successful device pairing events. This activity is significant as adversaries who gain unauthorized access to a user account may register a new MFA method to maintain persistence. If confirmed malicious, this could allow attackers to bypass existing security measures, maintain long-term access, and potentially escalate their privileges within the compromised environment.
T1098,T1098.005,T1556,T1556.006,T1621