OneLogin Failed High Risk Login


Description

A OneLogin attempt with a high risk factor (>50) resulted in a failed authentication.

Query · python

def rule(event):
    # check risk associated with this event
    if event.get("risk_score", 0) > 50:
        # a failed authentication attempt with high risk
        return str(event.get("event_type_id")) == "6"
    return False


def title(event):
    return f"A user [{event.get('user_name', '<UNKNOWN_USER>')}] failed a high risk login attempt"

Analyst notes

Investigate why this user login is tagged as high risk as well as whether this was caused by expected user activity.

Raw source OneLogin Failed High Risk Login · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Filename: onelogin_high_risk_failed_login.py
RuleID: "OneLogin.HighRiskFailedLogin"
DisplayName: "OneLogin Failed High Risk Login"
Enabled: true
LogTypes:
  - OneLogin.Events
Tags:
  - OneLogin
Severity: Low
Description: A OneLogin attempt with a high risk factor (>50) resulted in a failed authentication.
Reference: https://resources.onelogin.com/OneLogin_RiskBasedAuthentication-WP-v5.pdf
Runbook: Investigate why this user login is tagged as high risk as well as whether this was caused by expected user activity.
SummaryAttributes:
  - account_id
  - user_name
  - user_id
Tests:
  - Name: Normal Login Event
    ExpectedResult: false
    Log:
      {
        "event_type_id": "6",
        "actor_user_id": 123456,
        "actor_user_name": "Bob Cat",
        "user_id": 123456,
        "user_name": "Bob Cat",
      }
  - Name: Failed High Risk Login
    ExpectedResult: true
    Log:
      {
        "event_type_id": "6",
        "risk_score": 55,
        "actor_user_id": 123456,
        "actor_user_name": "Bob Cat",
        "user_id": 123456,
        "user_name": "Bob Cat",
      }


# ------ paired body: onelogin_high_risk_failed_login.py ------

def rule(event):
    # check risk associated with this event
    if event.get("risk_score", 0) > 50:
        # a failed authentication attempt with high risk
        return str(event.get("event_type_id")) == "6"
    return False


def title(event):
    return f"A user [{event.get('user_name', '<UNKNOWN_USER>')}] failed a high risk login attempt"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.