Auth0 Leaked Password Login Attempt


Description

Detect Auth0 Leaked Password Login Attempt

Query · python

from panther_core import PantherEvent


def rule(event: PantherEvent) -> bool:
    return event.deep_get("data", "type") == "pwd_leak"


def title(event: PantherEvent) -> str:
    ip_address = event.deep_get("data", "ip", default="NO_IP_FOUND")
    user_name = event.deep_get("data", "user_name", default="NO_USERNAME")
    event_title = (
        "Someone behind the IP address {} attempted to login with a leaked password "
        "with username {}"
    )

    return event_title.format(ip_address, user_name)
Raw source Auth0 Leaked Password Login Attempt · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Description: Detect Auth0 Leaked Password Login Attempt
DisplayName: "Auth0 Leaked Password Login Attempt"
Enabled: true
Filename: auth0_leaked_password_login_attempt.py
Severity: Medium
DedupPeriodMinutes: 60
Threshold: 1
LogTypes:
  - Auth0.Events
RuleID: "Auth0.Leaked.Password.Login.Attempt"
Tests:
  - ExpectedResult: true
    Log:
      log_id: "90020251001053916537654000000000000001223372122475524001"
      data:
        date: "2025-10-01 05:39:16.467000000"
        type: "pwd_leak"
        description: "Someone behind the IP address: 2601:140:9702:ee80:0000:1f55:93a7:e970 attempted to login with a leaked password. A shield to prevent this action was enabled, further attempts are blocked."
        connection: "Username-Password-Authentication"
        connection_id: "con_BvGURiLLdngYaT0D"
        client_id: "11Qpq1o8fbGgnZuFJnQCyjuC1ll8YFt0"
        ip: "2601:140:9702:ee80:9049:1f55:0000:e970"
        hostname: "auth.clientdomain.com"
        user_id: ""
        user_name: "denethor@lotr.com"
        log_id: "90020251001053916537654000000000000001223372122475524001"
        user_agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
    Name: FCOA Event

# ------ paired body: auth0_leaked_password_login_attempt.py ------

from panther_core import PantherEvent


def rule(event: PantherEvent) -> bool:
    return event.deep_get("data", "type") == "pwd_leak"


def title(event: PantherEvent) -> str:
    ip_address = event.deep_get("data", "ip", default="NO_IP_FOUND")
    user_name = event.deep_get("data", "user_name", default="NO_USERNAME")
    event_title = (
        "Someone behind the IP address {} attempted to login with a leaked password "
        "with username {}"
    )

    return event_title.format(ip_address, user_name)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.