Product
Okta MFA Disabled by User
2 rules 1 TTPDetection of Okta multi-factor authentication (MFA) being disabled by a user account, potentially indicating malicious activity or account compromise and leading to unauthorized access.
Okta Unauthorized Access to Application
2 rules 2 TTPsAnomalous activity indicating a user is attempting to access Okta applications they have not been assigned, potentially leading to data exposure or service disruption.
Okta ThreatInsight Detection of Credential Access Attempts
2 rules 1 TTPOkta ThreatInsight detected events indicating password spraying, login failures, and high counts of unknown user login attempts, potentially leading to unauthorized access and credential compromise.
Okta Suspicious Session Cookie Use
2 rules 1 TTPThis detection identifies the suspicious use of a session cookie by detecting multiple client values (IP, User Agent, etc.) changing for the same Device Token associated with a specific user, potentially indicating credential access and unauthorized account access.
Okta Successful Single Factor Authentication Attempt
2 rules 3 TTPs 2 IOCsSuccessful single-factor authentication events against the Okta Dashboard for accounts without Multi-Factor Authentication (MFA) enabled, potentially indicating account takeover attempts.
Okta Policy Modification or Deletion Detected
2 rules 1 TTPAn Okta policy was modified or deleted, potentially indicating unauthorized changes to security configurations within the Okta identity management platform by a malicious actor or insider.
Okta MFA Reset or Deactivation Attempt
2 rules 1 TTPAn attacker attempts to disable or reset multi-factor authentication (MFA) for a user account in Okta, potentially leading to unauthorized access and account compromise.
Okta Identity Provider Lifecycle Modifications
2 rules 1 TTPDetection of modifications to Okta Identity Provider (IDP) lifecycle events, such as creation, activation, deactivation, and deletion, which can indicate potential security breaches or misconfigurations.
Okta Authentication Failed During MFA Challenge
2 rules 3 TTPsDetection of failed authentication attempts during Okta MFA challenges, potentially indicating compromised credentials and attempts to bypass MFA.
Okta API Token Creation Detection
2 rules 1 TTPDetection of new Okta API token creation, potentially indicating account compromise or unauthorized access leading to persistence and administrative control.
Okta API Token Creation
2 rules 1 TTPDetection of Okta API token creation events which can indicate malicious persistence activity.
Okta New Device Enrollment Detection
2 rules 1 TTPDetection of new device enrollments in Okta, potentially indicating account takeover or unauthorized access by an adversary.