Skip to content
Notifications
Clear all

Just built a Python script to alert on anomalous ZPA access patterns.

5 Posts
5 Users
0 Reactions
10 Views
(@bluefox)
Reputable Member
Joined: 3 months ago
Posts: 228
Topic starter   [#27692]

Hey folks, been digging into our ZPA logs lately and realized we didn't have a good way to spot weird access patterns—like a user suddenly hitting an app from a new country at 3 AM.

So I threw together a quick Python script that taps into the ZPA API. It basically profiles "normal" access per user/app over a learning period, then fires off a Slack alert if something looks off. Super simple, but it's already caught a couple of suspicious logins we would've missed. Happy to share the core logic if anyone's interested!



   
Quote
(@amelia2)
Reputable Member
Joined: 3 months ago
Posts: 261
 

Nice. Are you tracking anything besides geo and time? IP velocity is another solid signal, especially for privileged accounts.

I'd also set a baseline period flag in the alert payload. Helps avoid noise from new users/apps.

Throw the script on a private gist. Would like to see how you're handling the ZPA pagination.


Ship it, but test it first


   
ReplyQuote
(@emilyl)
Honorable Member
Joined: 3 months ago
Posts: 527
 

Oh, IP velocity is a great point. I honestly hadn't thought that far ahead yet.

Could you explain what a good threshold for that might be? Like, flagging a login from a second country within an hour, or is it more nuanced than that?

The baseline period flag is super smart. I was already getting some weird alerts for a contractor who just started last week.



   
ReplyQuote
(@alexh99)
Estimable Member
Joined: 3 months ago
Posts: 119
 

Interesting approach. How did you decide on the length of your learning period? I've found that varies a lot by the volatility of the user base.

Also, does your script handle seasonality? We once got burned by not accounting for regular after-hours maintenance windows.



   
ReplyQuote
(@infra_auditor_nina)
Honorable Member
Joined: 6 months ago
Posts: 467
 

Learning period based on user volatility is putting the cart before the horse. How are you even defining 'volatility' in this context? That term needs a quantifiable metric tied to your alerting logic, otherwise it's just a guess.

On seasonality, if you're baking static maintenance windows into a behavioral baseline, you're creating a predictable blind spot. You should be tagging known-good activity and excluding it from the anomaly model, not training the model to think 3 AM logins from the NOC are normal for everyone.

Our postmortem on a similar system showed that approach masked a real compromise where an attacker piggybacked on a maintenance ticket.


- Nina


   
ReplyQuote