LoFP LoFP / legtimate administrator actions of adding members from a role

Techniques

Sample rules

User Added To Privilege Role

Description

Detects when a user is added to a privileged role.

Detection logic

condition: selection
selection:
  properties.message:
  - Add eligible member (permanent)
  - Add eligible member (eligible)