OneLogin: User Assumes Another Account via Event Type 3

Alerts on OneLogin events indicating a user assumed another user account via event_type_id 3.

FreeReviewedSigma · Low · v4
Product
onelogin
Service
onelogin.events
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-10-12
Updated
2026-07-31

What it detects

This rule flags OneLogin events where an authenticated user assumes or acts as another user account, as indicated by event_type_id 3. Such behavior is important because account assumption can enable unauthorized access, privilege misuse, or session impersonation depending on the user context. Detection relies on OneLogin event telemetry containing the specific event type identifier.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.