惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Blog — PlanetScale
Blog — PlanetScale
MyScale Blog
MyScale Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学
Vercel News
Vercel News
D
Docker
博客园 - 聂微东
T
Tailwind CSS Blog
aimingoo的专栏
aimingoo的专栏
云风的 BLOG
云风的 BLOG
D
DataBreaches.Net
B
Blog RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - Franky
Microsoft Security Blog
Microsoft Security Blog
美团技术团队
F
Fortinet All Blogs
MongoDB | Blog
MongoDB | Blog
T
The Blog of Author Tim Ferriss
GbyAI
GbyAI
N
Netflix TechBlog - Medium
G
Google Developers Blog
腾讯CDC

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Monitor 1Password with Datadog Cloud SIEM
Nimisha Saxena, Dayspring Johnson · 2023-07-27 · via Datadog | The Monitor blog
Nimisha Saxena

Nimisha Saxena

Dayspring Johnson

Dayspring Johnson

1Password is a password manager that helps organizations reduce the use of weak and reused credentials across their teams. Because your organization uses 1Password to store highly sensitive information, including passwords, access keys, and secret tokens, monitoring logs generated by activity in your 1Password environment can be useful, as unexpected patterns of behavior could indicate malicious activity by attackers.

We’re pleased to announce that Datadog now offers an integration with 1Password that collects and processes your 1Password logs so you can monitor them in real time. The integration also provides detection rules in Datadog Cloud SIEM that enable you to quickly detect suspicious activities that might signal an attack, such as credential theft or brute-forcing.

In this post, we’ll cover how to:

  • Visualize 1Password activity in real time using Datadog’s out-of-the-box 1Password dashboard

  • Uncover suspicious activity in your 1Password logs using Datadog Cloud SIEM

1password-image-5

Visualize 1Password activity in real time using Datadog’s out-of-the-box 1Password dashboard

Datadog’s integration with 1Password collects logs using 1Password Events API, which generates three types of logs:

  • Sign-in attempts: These logs include the name and IP address of the user who attempted to sign in to the account, when the attempt was made, and—for failed attempts—the cause of the failure, such as an incorrect password, key, or second factor.

  • Item usage: This type of log contains actions that describe how an item—e.g., a password or other credential—was used. Possible values for action include fill, enter-item-edit-mode, export, share, secure-copy, reveal, select-sso-provider, server-create, server-update, and server-fetch.

  • Audit events: These logs include actions performed by team members in a 1Password account, such as changes made to the account, vaults, groups, users, and more.

Once you enable the integration, Datadog’s out-of-the-box log processing pipeline will automatically parse and normalize your 1Password logs to structure them for easier analysis and correlation with your other log sources in Datadog.

After parsing your 1Password logs, Datadog will then populate the out-of-the-box 1Password overview dashboard with insights into security-related events from your 1Password values, items, and users. Widgets include toplists showing the most frequent and infrequent events, and a geolocation map that shows you the country of origin of sign-in attempts.

1password-image-1
1password-image-2

By aggregating critical insights from your 1Password environment into a single pane of glass, this dashboard helps you set a baseline for normal 1Password activity across your organization, so you can more easily identify abnormal patterns that could indicate an attack.

Uncover suspicious activity in your 1Password logs using Datadog Cloud SIEM

Datadog uses the three types of logs generated by the 1Password’s events API to identify suspicious activities that may occur within your 1Password tenant and generates Security Signals to alert you so you can investigate. After you enable the integration, Datadog Cloud SIEM will automatically analyze all of your 1Password logs in real time and evaluate them against multiple out-of-the-box detection rules. These rules identify various malicious activities, such as item exfiltration attempts, impossible travel events, item modification attempts, and more.

Some of these rules search for 1Password item usage actions that could indicate an attack. For example, the below rule uses the 1password-item-usages event type and the export event name to detect potential password exfiltration attempts.

1password-image-3

Other rules utilize the new value detection method to identify when an attribute, such as the event name familiar to a user, changes to a new value.

1password-image-4

These out-of-the-box detection rules generate Security Signals in Datadog Cloud SIEM to alert you to potential attacks quickly, so you can start mounting a response.

When you’ve identified a Security Signal from 1Password that requires investigation or remediation, you can use Datadog Workflow Automation to orchestrate an automated series of actions in response to the alert, using a customized workflow or one of our out-of-the-box Workflow Blueprints. For example, you can use the Investigate Security Incident and Create Case Workflow Blueprint to compile a Notebook in Datadog, where you can collect relevant information about the incident, then automatically send a Slack message to the appropriate team member so they can take additional remediation actions while you investigate further. The Workflow will then create a case in Datadog Case Management, which allows you to create a centralized, easily accessible workspace for investigating your security signals, so you can streamline the triage process and keep track of your progress in determining whether a Security Signal from 1Password is a true attack attempt.

Get started now

Datadog’s 1Password integration provides you with real-time monitoring to detect and secure your 1Password tenant against threats. If you’re already a Datadog customer, you can start exploring the new 1Password integration now. And if you’re not, get started today with a 14-day free trial.