OneLogin: User Assumes Another Account via Event Type 3

Alerts on OneLogin events indicating a user assumed another user account via event_type_id 3.

FreeReviewedSigma · Low · v4
Product
onelogin
Service
onelogin.events
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-10-12
Updated
2026-07-31
title: "OneLogin: User Assumes Another Account via Event Type 3"
id: 3c333d0d-122e-4cab-8331-3f390d2a7008
status: test
description: This rule flags OneLogin events where an authenticated user assumes or acts as another user account, as indicated by event_type_id 3. Such behavior is important because account assumption can enable unauthorized access, privilege misuse, or session impersonation depending on the user context. Detection relies on OneLogin event telemetry containing the specific event type identifier.
references:
  - https://developers.onelogin.com/api-docs/1/events/event-resource
  - https://github.com/SigmaHQ/sigma/blob/master/rules/identity/onelogin/onelogin_assumed_another_user.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-10-12
modified: 2022-12-25
tags:
  - attack.impact
logsource:
  product: onelogin
  service: onelogin.events
detection:
  selection:
    event_type_id: 3
  condition: selection
falsepositives:
  - Unknown
level: low
license: DRL-1.1
related:
  - id: 62fff148-278d-497e-8ecd-ad6083231a35
    type: derived