Ping

Telemetry Evidence

These values show how indexed rules identify Ping telemetry.

Kusto

  • Queried source table PingFederateEvent (11 rules)

Splunk

  • Data source PingID (4 rules)

Detection Rules

Kusto #

Show 1 more

Splunk #

  • PingID Mismatch Auth Source and Verification Response source medium: The following analytic identifies discrepancies between the IP address of an authentication event and the IP address of the verification response event, focusing on differences in the originating countries. It leverages JSON logs from PingID, comparing the 'auth_Country' and 'verify_Country' fields. This activity is significant as it may indicate suspicious sign-in behavior, such as account compromise or unauthorized access attempts. If confirmed malicious, this could allow attackers to bypass authentication mechanisms, potentially leading to unauthorized access to sensitive systems and data.T1098, T1098.005, T1556, T1556.006, T1621
  • PingID Multiple Failed MFA Requests For User source medium: The following analytic identifies multiple failed multi-factor authentication (MFA) requests for a single user within a PingID environment. It triggers when 10 or more MFA prompts fail within 10 minutes, using JSON logs from PingID. This activity is significant as it may indicate an adversary attempting to bypass MFA by bombarding the user with repeated authentication requests. If confirmed malicious, this could lead to unauthorized access, as the user might eventually accept the fraudulent request, compromising the security of the account and potentially the entire network.T1078, T1110, T1621
  • PingID New MFA Method After Credential Reset sourceT1098, T1098.005, T1556, T1556.006, T1621
  • PingID New MFA Method Registered For User source medium: The following analytic detects the registration of a new Multi-Factor Authentication (MFA) method for a PingID (PingOne) account. It leverages JSON logs from PingID, specifically looking for successful device pairing events. This activity is significant as adversaries who gain unauthorized access to a user account may register a new MFA method to maintain persistence. If confirmed malicious, this could allow attackers to bypass existing security measures, maintain long-term access, and potentially escalate their privileges within the compromised environment.T1098, T1098.005, T1556, T1556.006, T1621