BETA - Sensitive 1Password Item Accessed


Description

Alerts when a user defined list of sensitive items in 1Password is accessed

Query · python

"""
This rule requires the use of the Lookup Table feature currently in Beta in Panther, 1Password
logs reference items by their UUID without human-friendly titles. The instructions to create a
lookup table to do this translation can be found at :

 https://docs.runpanther.io/guides/using-lookup-tables-1password-uuids

The steps detailed in that document are required for this rule to function as intended.
"""

# Add the human-readable names of 1Password items you want to monitor
SENSITIVE_ITEM_WATCHLIST = ["demo_item"]


def rule(event):
    return (
        event.deep_get("p_enrichment", "1Password Translation", "item_uuid", "title")
        in SENSITIVE_ITEM_WATCHLIST
    )


def title(event):
    return f"A Sensitive 1Password Item was Accessed by user {event.deep_get('user', 'name')}"


def alert_context(event):
    context = {
        "user": event.deep_get("user", "name"),
        "item_name": event.deep_get("p_enrichment", "1Password Translation", "item_uuid", "title"),
        "client": event.deep_get("client", "app_name"),
        "ip_address": event.udm("source_ip"),
        "event_time": event.get("timestamp"),
    }

    return context
Raw source BETA - Sensitive 1Password Item Accessed · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Filename: onepassword_lut_sensitive_item_access.py
RuleID: "OnePassword.Lut.Sensitive.Item"
DedupPeriodMinutes: 30
DisplayName: "BETA - Sensitive 1Password Item Accessed"
Enabled: false
LogTypes:
  - OnePassword.ItemUsage
Reference: https://support.1password.com/1password-com-items/
Severity: Low
Description: Alerts when a user defined list of sensitive items in 1Password is accessed
SummaryAttributes:
  - p_any_ip_addresses
  - p_any_emails
Tags:
  - Configuration Required
  - 1Password
  - Lookup Table
  - Credential Access:Unsecured Credentials
Status: Experimental
Reports:
  MITRE ATT&CK:
    - TA0006:T1552
Tests:
  - Name: 1Password - Sensitive Item Accessed
    ExpectedResult: true
    Log:
      {
        "client":
          {
            "app_name": "1Password Browser Extension",
            "app_version": "20195",
            "ip_address": "1.1.1.1",
            "os_name": "MacOSX",
            "os_version": "10.15.7",
            "platform_name": "Chrome",
            "platform_version": "98.0.4758.102",
          },
        "item_uuid": "1234",
        "p_enrichment":
          {
            "1Password Translation":
              {
                "item_uuid":
                  {
                    "title": "demo_item",
                    "updatedAt": "2022-02-14 17:44:50.000000000",
                    "uuid": "12344321",
                  },
              },
          },
        "p_log_type": "OnePassword.ItemUsage",
        "timestamp": "2022-02-23 22:11:50.591",
        "user":
          {
            "email": "homer@springfield.gov",
            "name": "Homer Simpson",
            "uuid": "12345",
          },
        "uuid": "12345",
        "vault_uuid": "54321",
      }
  - Name: 1Password - Non-Sensitive Item Accessed
    ExpectedResult: false
    Log:
      {
        "client":
          {
            "app_name": "1Password Browser Extension",
            "app_version": "20195",
            "ip_address": "1.1.1.1",
            "os_name": "MacOSX",
            "os_version": "10.15.7",
            "platform_name": "Chrome",
            "platform_version": "98.0.4758.102",
          },
        "item_uuid": "1234",
        "p_enrichment":
          {
            "1Password Translation":
              {
                "item_uuid":
                  {
                    "title": "not_sensitive",
                    "updatedAt": "2022-02-14 17:44:50.000000000",
                    "uuid": "12344321",
                  },
              },
          },
        "p_log_type": "OnePassword.ItemUsage",
        "timestamp": "2022-02-23 22:11:50.591",
        "user":
          {
            "email": "homer@springfield.gov",
            "name": "Homer Simpson",
            "uuid": "12345",
          },
        "uuid": "12345",
        "vault_uuid": "54321",
      }

# ------ paired body: onepassword_lut_sensitive_item_access.py ------

"""
This rule requires the use of the Lookup Table feature currently in Beta in Panther, 1Password
logs reference items by their UUID without human-friendly titles. The instructions to create a
lookup table to do this translation can be found at :

 https://docs.runpanther.io/guides/using-lookup-tables-1password-uuids

The steps detailed in that document are required for this rule to function as intended.
"""

# Add the human-readable names of 1Password items you want to monitor
SENSITIVE_ITEM_WATCHLIST = ["demo_item"]


def rule(event):
    return (
        event.deep_get("p_enrichment", "1Password Translation", "item_uuid", "title")
        in SENSITIVE_ITEM_WATCHLIST
    )


def title(event):
    return f"A Sensitive 1Password Item was Accessed by user {event.deep_get('user', 'name')}"


def alert_context(event):
    context = {
        "user": event.deep_get("user", "name"),
        "item_name": event.deep_get("p_enrichment", "1Password Translation", "item_uuid", "title"),
        "client": event.deep_get("client", "app_name"),
        "ip_address": event.udm("source_ip"),
        "event_time": event.get("timestamp"),
    }

    return context

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.