foxsec-pipeline icon indicating copy to clipboard operation
foxsec-pipeline copied to clipboard

[authprofile] Alert on unknown users for specific systems

Open kkleemola opened this issue 3 years ago • 0 comments

For resources we expect all users to have access monitoring set up for, create an alert if an unknown user accesses it.

This will likely catch legitimate access for which we have gaps in monitoring so we should alert with something to call attention to it (like a @ here in slack), but not page.

kkleemola avatar Aug 06 '20 14:08 kkleemola