Hub
Cloud

Yandex 360 Organization Audit

Native Yandex 360 organization audit items for browser sign-ins and personal Disk file activity, for detection testing. Recurring episodes chain a sign-in, file view, public link and download of the same file.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/cloud-yandex-360-audit/generator.yml \
  --id yandex-360 \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
id_cookie.setSuccessful browser sign-in, service ID8.3% measured shareauthentication
disk_fs-viewView an existing personal file, service Web44.1% measured sharefile
disk_fs-get-download-urlAuthenticated owner downloads a file, service Web27.2% measured sharefile
disk_fs-storeEdit an existing file, service Web9.0% measured sharefile
disk_fs-set-publicPublish a currently private file link5.7% measured sharefile
disk_fs-set-privateRemove an existing owner/file link5.7% measured sharefile

Realism Features

  • One event per minute at a random second, about 1,440 per day; about 0.4% of minutes stay empty, where a download would complete the chain. Six accounts own three or four existing files each and work in short single-address browser sessions, from a usual or the shared alternate address; up to three sessions interleave.
  • Sharing sessions publish a currently private file of the owner with employees or all read rights (55/45), usually after opening it. Every link removal follows a successful publication of the same owner/file link: the owner removes it through a logged website operation within a few minutes of a removal time drawn 30-50 minutes after publication (holds 30-58 minutes); this is owner maintenance, not automatic expiry.
  • The alternate address, the admin account and every three-step part of the chain also occur in background; only the full ordered sequence on one file within 15 minutes of the sign-in is episode-only, and past 15 minutes ordinary sessions complete it at a natural rate. An account named admin does not establish administrator rights, and the chain does not prove anonymous retrieval or exfiltration.
  • The sign-in item covers 16/16 structural paths of the published example, including the request_id shape. Disk items cover the documented metadata fields, but no complete current-API Disk record was found, so Disk request IDs and the disk:/ path form are inferred and raw fidelity is unverified.
  • Addresses are 2001:db8::/32 documentation IPv6 in /128 form; identities and IDs are synthetic. Rates, weights and timing describe a synthetic busy-browser organization, not measured production frequencies. Only successful operations are modeled.

Sample Output

{
  "event": {
    "idempotency_id": "2c6b4908-a519-4de2-ad61-0ae925dacba2",
    "ip": "2001:db8:8005:f00:61ce:682c:bca4:42e5/128",
    "is_system": false,
    "meta": {
      "device_id": "",
      "revision": "1"
    },
    "occurred_at": "2026-10-01T16:01:22+00:00",
    "org_id": 1234567,
    "request_id": "@5756,1790870482.6881498,6343957899868700,8565f057755f1966cf13c1ed822b5246a7,1130000000123456,admin@corp.example",
    "service": "ID",
    "status": "Success",
    "type": "id_cookie.set",
    "uid": 1130000000123456
  },
  "user_login": "admin@corp.example",
  "user_name": "\u0421\u043e\u043a\u043e\u043b\u043e\u0432 \u0410\u043b\u0435\u043a\u0441\u0435\u0439"
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd recurring episodes; false produces only background
anomaly_interval_hours24Average spacing between episode starts, 6 to 8,760; the first falls within the first interval (at most 24 h), each later one in a window of a quarter of the interval (at most 6 h) centred one interval after the previous actual start
org_id1234567Positive integer organization ID
organization_domaincorp.exampleDomain for the five sampled employee logins
alternate_ip2001:db8:8005:f00:61ce:682c:bca4:42e5/128Alternate client address shared by all owners in both modes
compromised_loginadmin@corp.exampleExtra modeled account, also ordinary; the name is kept for compatibility
compromised_uid1130000000123456Positive integer UID distinct from the five sampled owners
compromised_nameСоколов АлексейExtra account's display name
compromised_usual_ip2001:db8:b081:b42d::1:90/128Extra account's usual client address
sensitive_pathdisk:/finance/payroll-2026.xlsxFile held by the extra account and by sampled owners that list it
sensitive_media_typespreadsheetNative media category of that file: document or spreadsheet

Related Generators