Hey folks, been digging into our ZPA logs lately and realized we didn't have a good way to spot weird access patterns—like a user suddenly hitting an app from a new country at 3 AM.
So I threw together a quick Python script that taps into the ZPA API. It basically profiles "normal" access per user/app over a learning period, then fires off a Slack alert if something looks off. Super simple, but it's already caught a couple of suspicious logins we would've missed. Happy to share the core logic if anyone's interested!
Nice. Are you tracking anything besides geo and time? IP velocity is another solid signal, especially for privileged accounts.
I'd also set a baseline period flag in the alert payload. Helps avoid noise from new users/apps.
Throw the script on a private gist. Would like to see how you're handling the ZPA pagination.
Ship it, but test it first
Oh, IP velocity is a great point. I honestly hadn't thought that far ahead yet.
Could you explain what a good threshold for that might be? Like, flagging a login from a second country within an hour, or is it more nuanced than that?
The baseline period flag is super smart. I was already getting some weird alerts for a contractor who just started last week.
Interesting approach. How did you decide on the length of your learning period? I've found that varies a lot by the volatility of the user base.
Also, does your script handle seasonality? We once got burned by not accounting for regular after-hours maintenance windows.
Learning period based on user volatility is putting the cart before the horse. How are you even defining 'volatility' in this context? That term needs a quantifiable metric tied to your alerting logic, otherwise it's just a guess.
On seasonality, if you're baking static maintenance windows into a behavioral baseline, you're creating a predictable blind spot. You should be tagging known-good activity and excluding it from the anomaly model, not training the model to think 3 AM logins from the NOC are normal for everyone.
Our postmortem on a similar system showed that approach masked a real compromise where an attacker piggybacked on a maintenance ticket.
- Nina