Product
Unusual Spike in Concurrent Active Sessions by a User
3 TTPsAn Elastic machine learning rule detects an unusual spike in concurrent active Okta sessions initiated by a user, indicating potential adversary abuse of valid credentials for privilege escalation or persistence through the execution of multiple privileged operations.
Spike in User Account Management Events
5 TTPsElastic Security's machine learning rule detects an unusual spike in Windows user account management events, including account creation, modification, or deletion, indicating potential privilege escalation or unauthorized activity by an adversary.
Okta User Risk Threshold Exceeded via Aggregated Suspicious Activities
2 rules 2 TTPsThis correlation identifies when a user exceeds a risk threshold based on multiple suspicious Okta activities by aggregating risk events from 'Suspicious Okta Activity,' 'Okta Account Takeover,' and 'Okta MFA Exhaustion' analytic stories, highlighting potentially compromised user accounts exhibiting multiple TTPs that could lead to unauthorized access, privilege escalation, or persistence.
UNC6671 BlackFile Vishing Extortion Campaign Targeting Microsoft 365 and Okta
2 rules 8 TTPs 5 IOCsUNC6671, operating under the "BlackFile" brand, conducts a sophisticated extortion campaign targeting organizations through voice phishing (vishing) and single sign-on (SSO) compromise, using adversary-in-the-middle (AiTM) techniques to bypass MFA and exfiltrate sensitive corporate data.
Unusual Spike in Okta User Lifecycle Management Change Events
2 rules 4 TTPsA machine learning job has identified an unusual spike in Okta user lifecycle management change events, indicating potential privileged access activity where threat actors may manipulate user accounts to gain higher access rights or persist within the environment.
Okta Policy Rule Modification or Deletion
2 rules 1 TTPAn Okta policy rule was modified or deleted, potentially weakening security controls.
Okta Initial Access via Proxy
2 rules 1 TTPDetection of a first-time user session started via a proxy, potentially indicating unauthorized initial access.
Okta Password Spray Attempt Detection
2 rules 1 TTPDetection of Okta password spraying attempts by identifying multiple failed login attempts from different source IPs targeting the same user account.
Okta Identity Provider Creation Detected
3 rules 2 TTPsAn adversary may create a rogue identity provider within Okta to establish persistence and potentially escalate privileges by impersonating legitimate users or bypassing multi-factor authentication.
Okta User Account Created
2 rules 1 TTPDetection of new user account creation in Okta, which could indicate malicious activity related to credential access.
Okta Security Threat Detected
2 rules 1 TTPThis alert detects when Okta's ThreatInsight identifies a security threat within an Okta environment, potentially indicating command and control activity.
Okta Admin Role Assignment Creation
2 rules 1 TTPDetection of new admin role assignments in Okta, potentially indicating privilege escalation or persistence attempts by malicious actors.
Okta End-User Reports Suspicious Account Activity
2 rules 1 TTPAn Okta end-user reports potentially suspicious activity on their account, indicating possible compromise or unauthorized access.
Okta User Logins from Multiple Cities Within 24 Hours
2 rules 2 TTPsThis analytic identifies instances where the same Okta user logs in from different cities within a 24-hour period, potentially indicating a compromised account and leading to account takeovers and data breaches.
Okta Group Lifecycle Change Spike Indicating Privilege Escalation
2 rules 4 TTPsA machine learning job has identified an unusual spike in Okta group lifecycle change events, indicating potential privilege escalation activity, where adversaries may be altering group structures to escalate privileges, maintain persistence, or facilitate lateral movement within an organization’s identity management system.
Unusual Source IP for Okta Privileged Operations Detected
2 rules 3 TTPsA machine learning job has identified a user performing privileged operations in Okta from an uncommon source IP, indicating potential privileged access activity indicative of account compromise or privilege escalation.
Okta Session Hijacking via Multiple Device Token Hashes
2 rules 2 TTPsDetection of multiple device token hashes and source IPs for a single Okta session, indicating potential session hijacking and unauthorized access to Okta resources.
Empty GitHub Page Threat Brief
1 rule 1 TTPThis brief analyzes a GitHub page which appears to be a placeholder or error, containing no actionable threat intelligence data.
Okta Alerts Following Unusual Proxy Authentication
2 rules 1 TTPAttackers use proxy infrastructure to mask their origin when using stolen Okta credentials, and this rule correlates the first occurrence of an Okta user session started via a proxy with subsequent Okta security alerts for the same user.
Okta Unauthorized Application Access Attempt
3 rulesThis brief describes a detection for unauthorized application access attempts within an Okta environment, indicating a potential security breach or misconfiguration.
Okta Multiple Users Failing Authentication From Single IP
2 rules 1 TTPMultiple users failing to authenticate from a single IP address within a short timeframe in Okta indicates potential brute-force or password spraying attacks, leading to unauthorized access and data breaches.
Okta Multiple Failed MFA Requests Indicate Potential MFA Bypass Attempt
2 rules 1 TTPAn adversary may attempt to bypass MFA by bombarding a user with repeated authentication requests, potentially leading to unauthorized access and system compromise.
Okta Multiple Account Lockouts Indicative of Password Spraying
2 rules 1 TTPMultiple Okta accounts locked out within a 5-minute period, detected via aggregated user.account.lock events, may indicate a password spraying attack leading to potential account takeovers.
Okta Group Privilege Change Spike via ML Detection
2 rules 4 TTPsA machine learning job has identified an unusual spike in Okta group privilege change events, indicating potential privileged access activity where attackers might be elevating privileges by adding themselves or compromised accounts to high-privilege groups, enabling further access or persistence.
Okta Group Application Assignment Spike Indicates Privilege Escalation
2 rules 4 TTPsA machine learning job identified a spike in Okta group application assignment changes, potentially indicating threat actors escalating privileges, maintaining persistence, or moving laterally by assigning applications to groups.
Okta FastPass Phishing Attempt Detection
2 rules 1 TTPOkta FastPass detected and prevented a phishing attempt, indicating a user was likely targeted with a credential harvesting attack.
Okta Application Sign-On Policy Modified or Deleted
2 rules 1 TTPAttackers may modify or delete Okta application sign-on policies to weaken security controls, potentially leading to unauthorized access and data breaches.
Okta Application Modified or Deleted
2 rules 1 TTPDetects when an Okta application is modified or deleted, potentially indicating unauthorized changes or removal of critical applications.
Okta API Token Revoked
2 rules 1 TTPDetection of Okta API token revocation events, indicating potential unauthorized access or compromise.
Geographic Improbable Location Detection
2 rules 1 TTPDetection of user logins originating from geographically distant locations within a short timeframe, indicative of potential Remote Employment Fraud or compromised credentials.
Detection of Okta Administrator Role Assignment to User or Group
2 rules 1 TTPDetects the assignment of an Okta administrator role to a user or group, potentially indicating privilege escalation or persistence attempts by malicious actors.
Okta User Risk Threshold Exceeded
2 rules 3 TTPsA user exceeding a risk threshold in Okta indicates a potential account compromise, leveraging Enterprise Security's Risk Framework by aggregating risk events from multiple suspicious Okta activities, which may lead to unauthorized access and privilege escalation.
Okta User Session Start via Anonymizing Proxy Service
2 rules 1 TTPDetection of Okta user sessions initiated through anonymizing proxy services, potentially indicating malicious activity or attempts to evade security controls.
Okta User Account Lockout Detection
2 rules 1 TTPDetection of an Okta user account lockout, which may indicate brute-force attempts or other malicious activity targeting user accounts.
Okta Privileged Operations from Unusual Host Name Detected
2 rules 2 TTPsA machine learning job detected a user performing privileged operations in Okta from an uncommon device, potentially indicating a compromised account or insider threat attempting privilege escalation.
Okta Group Membership Spike Detection
2 rules 4 TTPsA machine learning job has identified an unusual spike in Okta group membership events, indicating potential privileged access activity where attackers or malicious insiders might be adding accounts to privileged groups to escalate their access, potentially leading to unauthorized actions or data breaches.
Okta Credential Stuffing Attempt Detection
2 rules 1 TTPThis brief focuses on detecting credential stuffing attacks against Okta, characterized by multiple failed login attempts from a single source, potentially indicating automated attempts to compromise user accounts.
Masquerading Business Application Installers
2 rules 4 TTPsAttackers masquerade malicious executables as legitimate business application installers to trick users into downloading and executing malware, leveraging defense evasion and initial access techniques.
Okta Device Token Brute-Force Attempt
2 rules 1 TTPAn adversary attempts to compromise Okta accounts by brute-forcing device tokens to bypass multi-factor authentication (MFA) and gain unauthorized access.