LoFP LoFP / legtimate administrator actions of removing members from a role

Techniques

Sample rules

Bulk Deletion Changes To Privileged Account Permissions

Description

Detects when a user is removed from a privileged role. Bulk changes should be investigated.

Detection logic

condition: selection
selection:
  properties.message:
  - Remove eligible member (permanent)
  - Remove eligible member (eligible)