monday Engineering
Read post

Reading Between the Boards: Hunting Threats on monday.com

A practical threat-hunting guide for monday.com Enterprise tenants, covering the full attack lifecycle from initial access through exfiltration. The post explains the platform's data model (boards, workspaces, user types, permission layers) and audit log schema, then walks through specific detection rules for brute-force login, password reset abuse, persistence via user invites and API tokens, privilege escalation through team-join requests, MFA disabling, bulk board exports, and AI agent-based exfiltration. It concludes with a kill-chain correlation approach that chains multiple audit events by user_id to surface high-confidence account takeover scenarios.

    #security
Jun 30•12m read time•From engineering.monday.com
Post cover image
Table of contents
About the PlatformThe Threat-Hunting MindsetWhere the Data LivesThe Audit LogSchemaTraps before you huntThe Chapters of an AttackWhat Does Initial Access Look Like in monday.com?Did they really forget their password?What Does Persistence Look Like in monday.com?What Does Privilege Escalation Look Like in monday.com?What Does Defense Evasion Look Like in monday.com?What Does Exfiltration Look Like in monday.com?Exfiltration through AI agentsMonitoring the Export Account Data featureCorrelation: Chaining the Kill ChainTakeawaysmonday.com’s built-in mitigations
544 Impressions
monday Engineering's image
monday Engineering

Monday is a blog or publication focused on productivity, time management, and personal development. ...

37 Followers

•

416 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard