Atlassian user invited to organization as an organization administrator

This rule is part of a beta feature. To learn more, contact Support.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Goal

Detect when an Atlassian user is invited to the organization with the organizational administrator role.

Strategy

This rule monitors Atlassian organization audit logs for when a user is invited to the organization with the organizational administrator role. An attacker may try to invite an additional identity to the organization with high-level privileges.

Triage and response

  1. Determine if the user {{@usr.email}} intended to invite the target user as an organizational administrator:
    • Is there a related ticket tracking this change?
    • Is {{@usr.email}} aware of this activity?
    • Is the network metadata associated with the activity unusual for this user?
  2. If the results of the triage indicate that {{@usr.email}} was not aware of this activity or it did not originate from a known network, begin your company’s incident response process, and start an investigation.