- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
This detection identifies when Zoom user accounts are elevated to privileged roles (Admin or Co-Owner).
This detection monitors Zoom operation logs for user role elevation events. The rule focuses on events where a user’s role is changed to either “Co-Owner” or “Admin” roles. The detection analyzes events with @evt.category
of “User” and @evt.name
values of “Update” or “Batch Update” containing specific messages indicating role changes to privileged positions. Events are grouped by the email address of the user making these changes (@usr.email
).
Role elevation is significant because privileged accounts can perform sensitive actions such as managing users, modifying security settings, and changing organizational policies. Unauthorized elevation to these roles provides attackers with extensive capabilities to modify the Zoom environment and potentially maintain persistence.
{{@usr.email}}
) performed the role change and confirm legitimacy.