Duo Admin Policy Updated


Description

A Duo Administrator updated a Policy, which governs how users authenticate.

Query · python

from panther_duo_helpers import duo_alert_context


def rule(event):
    return event.get("action") == "policy_update"


def title(event):
    return (
        f"Duo: [{event.get('username', '<username_not_found>')}] "
        f"updated [{event.get('object', 'Duo Policy')}]."
    )


def alert_context(event):
    return duo_alert_context(event)
Raw source Duo Admin Policy Updated · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Description: A Duo Administrator updated a Policy, which governs how users authenticate.
DisplayName: "Duo Admin Policy Updated"
Enabled: true
Filename: duo_admin_policy_updated.py
Reference: https://duo.com/docs/policy#authenticators-policy-settings
Severity: Medium
Tests:
  - ExpectedResult: true
    Log:
      action: policy_update
      description: '{"adaptive_auth_display_unit": "days", "trusted_mobile_endpoint_policy": "no action", "adaptive_auth_hours": 0, "admin_email": "homer.simpson@simpsons.com", "allow_factor_u2f": false, "device_certificate_policy": "no action", "allow_factor_phone": false, "local_trusted_sessions_display_val": 0, "allow_adaptive_auth": false, "local_trusted_sessions_display_unit": "days", "allow_factor_sms": false}'
      isotimestamp: "2022-02-21 21:48:48"
      object: Global Policy
      timestamp: "2022-02-21 21:48:48"
      username: Homer Simpson
    Name: Policy Update
  - ExpectedResult: false
    Log:
      action: admin_login
      description: '{"ip_address": "1.2.3.4", "device": "123-456-123", "factor": "sms", "saml_idp": "OneLogin", "primary_auth_method": "Single Sign-On"}'
      isotimestamp: "2021-07-02 18:31:25"
      timestamp: "2021-07-02 18:31:25"
      username: Homer Simpson
    Name: Other event
DedupPeriodMinutes: 60
LogTypes:
  - Duo.Administrator
RuleID: "Duo.Admin.Policy.Updated"
Threshold: 1


# ------ paired body: duo_admin_policy_updated.py ------

from panther_duo_helpers import duo_alert_context


def rule(event):
    return event.get("action") == "policy_update"


def title(event):
    return (
        f"Duo: [{event.get('username', '<username_not_found>')}] "
        f"updated [{event.get('object', 'Duo Policy')}]."
    )


def alert_context(event):
    return duo_alert_context(event)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.