Zoom All Meetings Secured With One Option Disabled


Description

A Zoom User turned off your organization's requirement that all meetings are secured with one security option.

Query · python

def rule(event):
    operation_detail = event.get("operation_detail", "<NO_OPS_DETAIL>")
    operation_flag = (
        "Require that all meetings are secured with one security option: from On to Off"
    )

    return (
        event.get("action", "<NO_ACTION>") == "Update"
        and event.get("category_type", "<NO_CATEGORY_TYPE>") == "Account"
        and operation_flag in operation_detail
    )


def title(event):
    return (
        f"Zoom User [{event.get('operator', '<NO_OPERATOR>')}] turned off your organization's "
        f"requirement to secure all meetings with one security option."
    )

Analyst notes

Confirm this user acted with valid business intent and determine whether this activity was authorized.

Raw source Zoom All Meetings Secured With One Option Disabled · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Description: A Zoom User turned off your organization's requirement that all meetings are secured with one security option.
DisplayName: "Zoom All Meetings Secured With One Option Disabled"
Enabled: true
Filename: zoom_all_meetings_secured_with_one_option_disabled.py
Runbook: Confirm this user acted with valid business intent and determine whether this activity was authorized.
Reference: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0059862
Severity: Medium
Tests:
  - ExpectedResult: true
    Log:
      action: Update
      category_type: Account
      operation_detail: "Security  - Require that all meetings are secured with one security option: from On to Off"
      operator: example@example.io
      time: "2022-12-16 18:15:38"
    Name: Turn off
  - ExpectedResult: false
    Log:
      action: Update
      category_type: Account
      operation_detail: "Security  - Require that all meetings are secured with one security option: from Off to On"
      operator: example@example.io
      time: "2022-12-16 18:15:38"
    Name: Turn on
  - ExpectedResult: false
    Log:
      action: Update
      category_type: User
      operation_detail: "Update User example@example.io  - Job Title: set to Contractor"
      operator: homer@example.io
    Name: Non admin user update
DedupPeriodMinutes: 60
LogTypes:
  - Zoom.Operation
RuleID: "Zoom.All.Meetings.Secured.With.One.Option.Disabled"
Threshold: 1


# ------ paired body: zoom_all_meetings_secured_with_one_option_disabled.py ------

def rule(event):
    operation_detail = event.get("operation_detail", "<NO_OPS_DETAIL>")
    operation_flag = (
        "Require that all meetings are secured with one security option: from On to Off"
    )

    return (
        event.get("action", "<NO_ACTION>") == "Update"
        and event.get("category_type", "<NO_CATEGORY_TYPE>") == "Account"
        and operation_flag in operation_detail
    )


def title(event):
    return (
        f"Zoom User [{event.get('operator', '<NO_OPERATOR>')}] turned off your organization's "
        f"requirement to secure all meetings with one security option."
    )

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.