Yandex 360 Organization Audit
Native Yandex 360 organization audit items for browser sign-ins and personal Disk file activity, for detection testing. Recurring episodes chain a sign-in, file view, public link and download of the same file.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/cloud-yandex-360-audit/generator.yml \
--id yandex-360 \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| id_cookie.set | Successful browser sign-in, service ID | 8.3% measured share | authentication |
| disk_fs-view | View an existing personal file, service Web | 44.1% measured share | file |
| disk_fs-get-download-url | Authenticated owner downloads a file, service Web | 27.2% measured share | file |
| disk_fs-store | Edit an existing file, service Web | 9.0% measured share | file |
| disk_fs-set-public | Publish a currently private file link | 5.7% measured share | file |
| disk_fs-set-private | Remove an existing owner/file link | 5.7% measured share | file |
Realism Features
- One event per minute at a random second, about 1,440 per day; about 0.4% of minutes stay empty, where a download would complete the chain. Six accounts own three or four existing files each and work in short single-address browser sessions, from a usual or the shared alternate address; up to three sessions interleave.
- Sharing sessions publish a currently private file of the owner with employees or all read rights (55/45), usually after opening it. Every link removal follows a successful publication of the same owner/file link: the owner removes it through a logged website operation within a few minutes of a removal time drawn 30-50 minutes after publication (holds 30-58 minutes); this is owner maintenance, not automatic expiry.
- The alternate address, the admin account and every three-step part of the chain also occur in background; only the full ordered sequence on one file within 15 minutes of the sign-in is episode-only, and past 15 minutes ordinary sessions complete it at a natural rate. An account named admin does not establish administrator rights, and the chain does not prove anonymous retrieval or exfiltration.
- The sign-in item covers 16/16 structural paths of the published example, including the request_id shape. Disk items cover the documented metadata fields, but no complete current-API Disk record was found, so Disk request IDs and the disk:/ path form are inferred and raw fidelity is unverified.
- Addresses are 2001:db8::/32 documentation IPv6 in /128 form; identities and IDs are synthetic. Rates, weights and timing describe a synthetic busy-browser organization, not measured production frequencies. Only successful operations are modeled.
Sample Output
{
"event": {
"idempotency_id": "2c6b4908-a519-4de2-ad61-0ae925dacba2",
"ip": "2001:db8:8005:f00:61ce:682c:bca4:42e5/128",
"is_system": false,
"meta": {
"device_id": "",
"revision": "1"
},
"occurred_at": "2026-10-01T16:01:22+00:00",
"org_id": 1234567,
"request_id": "@5756,1790870482.6881498,6343957899868700,8565f057755f1966cf13c1ed822b5246a7,1130000000123456,admin@corp.example",
"service": "ID",
"status": "Success",
"type": "id_cookie.set",
"uid": 1130000000123456
},
"user_login": "admin@corp.example",
"user_name": "\u0421\u043e\u043a\u043e\u043b\u043e\u0432 \u0410\u043b\u0435\u043a\u0441\u0435\u0439"
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add recurring episodes; false produces only background |
| anomaly_interval_hours | 24 | Average spacing between episode starts, 6 to 8,760; the first falls within the first interval (at most 24 h), each later one in a window of a quarter of the interval (at most 6 h) centred one interval after the previous actual start |
| org_id | 1234567 | Positive integer organization ID |
| organization_domain | corp.example | Domain for the five sampled employee logins |
| alternate_ip | 2001:db8:8005:f00:61ce:682c:bca4:42e5/128 | Alternate client address shared by all owners in both modes |
| compromised_login | admin@corp.example | Extra modeled account, also ordinary; the name is kept for compatibility |
| compromised_uid | 1130000000123456 | Positive integer UID distinct from the five sampled owners |
| compromised_name | Соколов Алексей | Extra account's display name |
| compromised_usual_ip | 2001:db8:b081:b42d::1:90/128 | Extra account's usual client address |
| sensitive_path | disk:/finance/payroll-2026.xlsx | File held by the extra account and by sampled owners that list it |
| sensitive_media_type | spreadsheet | Native media category of that file: document or spreadsheet |
Related Generators
AWS CloudTrail Management Events
AWS CloudTrail audit trail — API calls across EC2, IAM, STS, and S3 from a multi-account organization. Includes console logins, role assumptions, error injection, and 4 identity types.
AWS GuardDuty Findings
AWS GuardDuty threat detection findings across EC2, IAM, and S3 resources. Covers 8 categories — Recon, UnauthorizedAccess, Policy, Trojan, Impact, CryptoCurrency, Stealth, and Backdoor — with 27 finding types, 10 threat actor IPs, and geo/ASN enrichment.
AWS VPC Flow Logs
AWS VPC Flow Logs (v5) — network traffic records across multiple accounts, VPCs, and subnets. TCP/UDP/ICMP flows with ACCEPT/REJECT actions, NAT gateway traffic, and realistic byte/packet distributions.