Skip to main content

1Password firewall rules changed

ID:1password_firewall_rules_changed
Data type:1Password
Severity:
Low
MITRE ATT&CK:TA0112:T1686.001

Description

AlphaSOC detected a change to the account-level firewall rules in 1Password. These rules restrict the networks and locations from which users can access the account. An unauthorized change may allow access from attacker-controlled or otherwise untrusted infrastructure.

Impact

Weakening or removing firewall restrictions can expose the 1Password account to login attempts from networks that were previously blocked. If an attacker also has valid credentials or a compromised session, the change can help them access vaults and the secrets stored in them.

Severity

SeverityCondition
Low
1Password firewall rules changed

Investigation and Remediation

Review the 1Password audit event to identify the actor, the source network, and the firewall rule changes. Verify that the change was approved and that the affected networks are expected. If it was unauthorized, restore the intended firewall policy, revoke active sessions for the acting account, and investigate other administrative actions performed by that account.