Configuration Required - Sensitive 1Password Item Accessed


Description

Alerts when a user defined list of sensitive items in 1Password is accessed

Query · python

"""
This rule detects access to high sensitivity items in your 1Password account. 1Password references
these items by their UUID so the SENSITIVE_ITEM_WATCHLIST below allows for the mapping of UUID to
meaningful name.

There is an alternative method for creating this rule that uses Panther's lookup table feature,
(currently in beta). That rule can be found in the 1Password detection pack with the name
BETA - Sensitive 1Password Item Accessed (onepassword_lut_sensitive_item_access.py)
"""

SENSITIVE_ITEM_WATCHLIST = {"ecd1d435c26440dc930ddfbbef201a11": "demo_item"}


def rule(event):
    return event.get("item_uuid") in SENSITIVE_ITEM_WATCHLIST.keys()


def title(event):
    return f"A Sensitive 1Password Item was Accessed by user {event.deep_get('user', 'name')}"


def alert_context(event):
    context = {
        "user": event.deep_get("user", "name"),
        "item_name": event.deep_get("p_enrichment", "1Password Translation", "item_uuid", "title"),
        "client": event.deep_get("client", "app_name"),
        "ip_address": event.udm("source_ip"),
        "event_time": event.get("timestamp"),
    }

    return context
Raw source Configuration Required - Sensitive 1Password Item Accessed · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Filename: onepassword_sensitive_item_access.py
RuleID: "OnePassword.Sensitive.Item"
DedupPeriodMinutes: 30
DisplayName: "Configuration Required - Sensitive 1Password Item Accessed"
Enabled: false
LogTypes:
  - OnePassword.ItemUsage
Reference: https://support.1password.com/1password-com-items/
Severity: Low
Description: Alerts when a user defined list of sensitive items in 1Password is accessed
SummaryAttributes:
  - p_any_ip_addresses
  - p_any_emails
Tags:
  - Configuration Required
  - 1Password
  - Credential Access:Unsecured Credentials
Reports:
  MITRE ATT&CK:
    - TA0006:T1552
Tests:
  - Name: 1Password - Sensitive Item Accessed
    ExpectedResult: true
    Log:
      {
        "uuid": "ecd1d435c26440dc930ddfbbef201a11",
        "timestamp": "2022-02-23 20:27:17.071",
        "used_version": 2,
        "vault_uuid": "111111",
        "item_uuid": "ecd1d435c26440dc930ddfbbef201a11",
        "user":
          {
            "email": "homer@springfield.gov",
            "name": "Homer Simpson",
            "uuid": "2222222",
          },
        "client":
          {
            "app_name": "1Password Browser Extension",
            "app_version": "20195",
            "ip_address": "1.1.1.1.1",
            "os_name": "MacOSX",
            "os_version": "10.15.7",
            "platform_name": "Chrome",
            "platform_version": "4.0.4.102",
          },
        "p_log_type": "OnePassword.ItemUsage",
      }

  - Name: 1Password - Regular Item Usage
    ExpectedResult: false
    Log:
      {
        "uuid": "11111",
        "timestamp": "2022-02-23 20:27:17.071",
        "used_version": 2,
        "vault_uuid": "111111",
        "item_uuid": "1111111",
        "user":
          {
            "email": "homer@springfield.gov",
            "name": "Homer Simpson",
            "uuid": "2222222",
          },
        "client":
          {
            "app_name": "1Password Browser Extension",
            "app_version": "20195",
            "ip_address": "1.1.1.1.1",
            "os_name": "MacOSX",
            "os_version": "10.15.7",
            "platform_name": "Chrome",
            "platform_version": "4.0.4.102",
          },
        "p_log_type": "OnePassword.ItemUsage",
      }


# ------ paired body: onepassword_sensitive_item_access.py ------

"""
This rule detects access to high sensitivity items in your 1Password account. 1Password references
these items by their UUID so the SENSITIVE_ITEM_WATCHLIST below allows for the mapping of UUID to
meaningful name.

There is an alternative method for creating this rule that uses Panther's lookup table feature,
(currently in beta). That rule can be found in the 1Password detection pack with the name
BETA - Sensitive 1Password Item Accessed (onepassword_lut_sensitive_item_access.py)
"""

SENSITIVE_ITEM_WATCHLIST = {"ecd1d435c26440dc930ddfbbef201a11": "demo_item"}


def rule(event):
    return event.get("item_uuid") in SENSITIVE_ITEM_WATCHLIST.keys()


def title(event):
    return f"A Sensitive 1Password Item was Accessed by user {event.deep_get('user', 'name')}"


def alert_context(event):
    context = {
        "user": event.deep_get("user", "name"),
        "item_name": event.deep_get("p_enrichment", "1Password Translation", "item_uuid", "title"),
        "client": event.deep_get("client", "app_name"),
        "ip_address": event.udm("source_ip"),
        "event_time": event.get("timestamp"),
    }

    return context

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.