- Stolen credentials mode updated
Account login method removed
Admin accepted invitation
Admin enabled MFA
Admin exported data
Admin loaded data
Admin logged in
Admin removed
Admin role updated
API key added
API key removed
App approval status updated
App labels added
App labels removed
App notes updated
App owner ID updated
App sensitivity level updated
Auto-licensing toggled
Auto-unlicensing configuration updated
Blocked URLs added
Blocked URLs removed
Blocked URLs URL schema obfuscation toggled
Browser extension enumeration toggled
Clipboard custom regex pattern added
Clipboard blocking regex pattern removed
Cloned login page detection ignored domains added
Cloned login page detection ignored domains removed
Control rule added
Control rule updated
Control rule removed
Control rule toggled
Control rule reordered
Control rules updated via API
Custom detection created
Custom detection removed
Custom detection configuration updated
Custom login URL added
Custom login URL removed
Data retention configuration updated
Detection archive status updated
Detection classification updated
Detection screenshots toggled
Domain category blocking ignored domains added
Domain category blocking ignored domains removed
Domain enrichment toggled
Employees added to group
Employee disabled extension
Excluded extension domains added
Extended audit logging toggled
Excluded extension domains removed
Extension branding logo uploaded
Extension branding updated
Employee email updated
Employee name updated
Employee removed from group
Employees merged
Employees unmerged
Integration added
Integration completed
Integration removed
Label updated
Label removed
Leaked password check toggled
License assigned
License removed
Malicious browser extension detection excluded extensions added
Malicious browser extension detection excluded extensions removed
Malicious copy paste detection ignored domains added
Malicious copy paste detection ignored domains removed
MFA tracking exclusions updated
Monitor all domains toggled
Monitored domains added
Monitored domains removed
OAuth app approval status updated
Password protection URL masking toggled
Password protection ignore work apps toggled
Password protection ignored domains added
Password protection ignored domains removed
Phishing tool detection ignored domains added
Phishing tool detection ignored domains removed
Reused password exceptions updated
SAML SSO added
SAML SSO completed
SAML SSO default role updated
Session theft domains added
Session theft domains removed
Session theft marker rotated
Stolen credentials added
Stolen credentials removed
Telemetry rule added
Telemetry rule updated
Telemetry rule removed
Telemetry rule toggled
Telemetry rule reordered
Unsupported app support requested
Unsupported app support request cancelled
URL block page updated
Weak password custom words added
Weak password custom words removed
Webhook added
Webhook removed
App banner configured
App banner enabled
MFA enforcement apps updated
MFA enforcement settings updated
Phishing tool detection page updated
Phishing tool detection mode updated
SSO password protection ignored domains added
SSO password protection ignored domains removed
SSO password protection ignore work apps toggled
SSO password protection mode updated
SSO password protection page updated
SSO password protection URL masking toggled
Stolen credentials mode u...
An admin user has updated the mode of the stolen credentials feature.
Security
X-Signature
The unique identifier for the event. This can be used as an idempotency key.
Example:"c478966c-f927-411c-b919-179832d3d50c"
The unique identifier of the tenant the event belongs to.
Example:"4f9d2e7a-1b3c-4d5e-8f6a-7c8b9d0e1f2a"
When the event occurred, formatted as a UNIX timestamp (in seconds).
Example:1698604061
The description of the event. Note: this is subject to change and should not be used to match on this object.
Example:"user@example.com set the mode to off"
- https://api.pushsecurity.comhttps://api.pushsecurity.com/stolen-credentials-mode-updated
{ "version": "1", "id": "c478966c-f927-411c-b919-179832d3d50c", "tenantId": "4f9d2e7a-1b3c-4d5e-8f6a-7c8b9d0e1f2a", "timestamp": 1698604061, "category": "AUDIT", "description": "user@example.com set the mode to off", "object": "STOLEN_CREDENTIALS_MODE_UPDATED", "friendlyName": "Stolen credentials mode updated", "actor": { "source": "UI", "email": "string", "sourceIpAddress": "string", "userAgent": "string", "role": "OWNER" }, "new": { "mode": "string" } }