For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-kfa.md. A documentation index is available at /llms.txt.

Anomalous amount of failed sign-in attempts by 1Password user

Goal

Detect failed sign-in attempts from a 1Password user.

Strategy

This rule monitors 1Password logs to identify when an user generates an anomalous amount of failed sign-in events.

Triage and response

Investigate and determine if user {{@usr.email}} with failed sign-in events {{@evt.outcome}}, attempting to authenticate from IP address {{@network.client.ip}} should have access.

Changelog

Updated query by replacing @evt.category:*failed* with @evt.outcome:*failed*.