Panther low experimental python

GSuite User Advanced Protection Change

A user disabled advanced protection for themselves.

View Source

Detection Logic

def rule(event):
    if event.deep_get("id", "applicationName") != "user_accounts":
        return False

    return bool(event.get("name") == "titanium_unenroll")


def title(event):
    return (
        f"Advanced protection was disabled for user "
        f"[{event.deep_get('actor', 'email', default='<UNKNOWN_EMAIL>')}]"
    )

Field Validations

Loading…

Comments (0)

Loading comments...