Zoom
Telemetry Evidence
These values show how indexed rules identify Zoom telemetry.Kusto
ZoomLogs Panther
Zoom.Activity Zoom.Operation zoom
Detection Rules
Kusto #
- External User Access Enabled source low: 'This alerts when the account setting is changed to allow either external domain access or anonymous access to meetings.'
T1098,T1556 - Suspicious link sharing pattern source low: 'Alerts in links that have been shared across multiple Zoom chat channels by the same user in a short space if time. Adjust the threshold figure to change the number of channels a message needs to be posted in before an alert is raised.'
T1598 - User joining Zoom meeting from suspicious timezone source low: 'The alert shows users that join a Zoom meeting from a time zone other than the one the meeting was created in. You can also whitelist known good time zones in the tz_whitelist value using the tz database name format https://en.wikipedia.org/wiki/List_of_tz_database_time_zones'
T1078 - Zoom E2E Encryption Disabled source medium: 'This alerts when end to end encryption is disabled for Zoom meetings.'
T1040
Panther #
- GreyNoise V3 Malicious IP Activity source high: Detects when an IP address in any log event is classified as malicious or unknown by GreyNoise V3 internet scanner intelligence. Known business services and benign IPs are excluded.
T1595.001 - GTI/VirusTotal Threat Intelligence Indicator Match source high: Detects when an IP address, domain, or file hash in any log event matches a known malicious indicator from Google Threat Intelligence (GTI) / VirusTotal enrichment. Severity is elevated based on GTI's threat severity verdict and the number of vendors flagging the indicator as malicious.
T1595.001 - New User Account Created source informational: A new account was created
T1136 - OTX Threat Intelligence Indicator Match source high: Detects when an IP address in any log event matches a known threat indicator from AlienVault OTX pulse intelligence. Severity is elevated when the pulse includes a named adversary or known malware families.
T1595.001 - Sign In from Rogue State source medium: Detects when an entity signs in from a nation associated with cyber attacks
T1078.004 - Zoom All Meetings Secured With One Option Disabled source medium: A Zoom User turned off your organization's requirement that all meetings are secured with one security option.
- Zoom Automatic Sign Out Disabled source medium: A Zoom User turned off your organization's setting to automatically sign users out after a specified period of time.
- Zoom Meeting Passcode Disabled source low: Meeting passcode requirement has been disabled from usergroup
T1125 - Zoom New Meeting Passcode Required Disabled source medium: A Zoom User turned off your organization's setting to require passcodes for new meetings.
- Zoom Sign In Method Modified source medium: A Zoom User modified your organizations sign in method.
Show 3 more
- Zoom Sign In Requirements Changed source medium: A Zoom User changed your organization's sign in requirements.
- Zoom Two Factor Authentication Disabled source medium: A Zoom User disabled your organization's setting to sign in with Two-Factor Authentication.
- Zoom User Promoted to Privileged Role source medium: A Zoom user was promoted to a privileged role.