Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow 'applicationName=login for GSuite.ExternalMailForwarding` #1395

Merged
merged 1 commit into from
Oct 22, 2024

Conversation

ben-githubs
Copy link
Contributor

Background

A customer raised an issue with the current detection - email forwarding change events can come from applications with name user_accoutns or login. They observed events where applicationName=login did not raise alerts. We confirmed this behaviour and updated the rule.

Changes

  • restrict applicationName to login or user_accounts instead of just user_accounts

Testing

  • used a recent email forwarding event from our own logs as a test case

@ben-githubs ben-githubs requested a review from a team as a code owner October 21, 2024 14:54
Copy link

😱
looks like some things could be wrong with the packs

1 similar comment
Copy link

😱
looks like some things could be wrong with the packs

@arielkr256 arielkr256 added rules Real-time log data detections tuning detection tuning labels Oct 22, 2024
@arielkr256 arielkr256 enabled auto-merge (squash) October 22, 2024 14:17
@arielkr256 arielkr256 merged commit 09d2d70 into develop Oct 22, 2024
9 checks passed
@arielkr256 arielkr256 deleted the ASK-875/gsuite-email-forwarding-update branch October 22, 2024 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
rules Real-time log data detections tuning detection tuning
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants