Duo Admin New Admin API App Integration


Description

Identifies creation of new Admin API integrations for Duo.

Query · python

from panther_duo_helpers import deserialize_administrator_log_event_description, duo_alert_context


def rule(event):
    if event.get("action") == "integration_create":
        description = deserialize_administrator_log_event_description(event)
        integration_type = description.get("type")
        return integration_type == "Admin API"
    return False


def title(event):
    return (
        f"Duo: [{event.get('username', '<username_not_found>')}] "
        "created a new Admin API integration "
        f"to [{event.get('object', '<object_not_found>')}]"
    )


def alert_context(event):
    return duo_alert_context(event)
Raw source Duo Admin New Admin API App Integration · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Description: Identifies creation of new Admin API integrations for Duo.
DisplayName: "Duo Admin New Admin API App Integration"
Enabled: true
Filename: duo_admin_new_admin_api_app_integration.py
Reference: https://duo.com/docs/adminapi#overview
Severity: High
Tests:
  - ExpectedResult: true
    Log:
      action: integration_create
      description: '{"greeting": "", "notes": "", "offline_auth_enabled": 0, "offline_max_days": 0, "offline_max_attempts": 0, "type": "Admin API", "raw_type": "adminapi", "name": "Admin API", "self_service_allowed": false, "username_normalization_policy": "None", "missing_web_referer_policy": "deny", "networks_for_api_access": "", "group_access": ""}'
      isotimestamp: "2021-11-30 17:15:33"
      object: Admin API
      timestamp: "2021-11-30 17:15:33"
      username: Homer Simpson
    Name: Admin API Integration Created
  - ExpectedResult: false
    Log:
      action: integration_create
      description: '{"greeting": "", "notes": "", "offline_auth_enabled": 0, "offline_max_days": 0, "offline_max_attempts": 0, "type": "1Password", "raw_type": "1password", "name": "1Password", "self_service_allowed": false, "username_normalization_policy": "None", "missing_web_referer_policy": "deny", "networks_for_api_access": "", "group_access": ""}'
      isotimestamp: "2021-11-30 17:11:51"
      object: 1Password
      timestamp: "2021-11-30 17:11:51"
      username: Homer Simpson
    Name: Non Admin API Integration
  - ExpectedResult: false
    Log:
      action: user_update
      description: '{"phones": ""}'
      isotimestamp: "2021-07-02 18:31:56"
      object: homer.simpson@simpsons.io
      timestamp: "2021-07-02 18:31:56"
      username: Homer Simpson
    Name: Other Event
DedupPeriodMinutes: 60
LogTypes:
  - Duo.Administrator
RuleID: "Duo.Admin.New.Admin.API.App.Integration"
Threshold: 1


# ------ paired body: duo_admin_new_admin_api_app_integration.py ------

from panther_duo_helpers import deserialize_administrator_log_event_description, duo_alert_context


def rule(event):
    if event.get("action") == "integration_create":
        description = deserialize_administrator_log_event_description(event)
        integration_type = description.get("type")
        return integration_type == "Admin API"
    return False


def title(event):
    return (
        f"Duo: [{event.get('username', '<username_not_found>')}] "
        "created a new Admin API integration "
        f"to [{event.get('object', '<object_not_found>')}]"
    )


def alert_context(event):
    return duo_alert_context(event)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.