Platform / product
okta Sigma detection rules
24 community-maintained Sigma detection rules in the library target the okta platform. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.
Severity
Okta FastPass Phishing Detection
highDetects when Okta FastPass prevents a known phishing site.
okta · okta
Okta New Admin Console Behaviours
highDetects when Okta identifies new activity in the Admin Console.
okta · okta
Okta Suspicious Activity Reported by End-user
highDetects when an Okta end-user reports activity by their account as being potentially suspicious.
okta · okta
Okta User Session Start Via An Anonymising Proxy Service
highDetects when an Okta user session starts where the user is behind an anonymising proxy service.
okta · okta
Potential Okta Password in AlternateID Field
highDetects when a user has potentially entered their password into the username field, which will cause the password to be retained in log files.
okta · okta
Okta 2023 Breach Indicator Of Compromise
mediumDetects new user account creation or activation with specific names related to the Okta Support System 2023 breach. This rule can be enhanced by filtering out known and legitimate username used in your environnement.
okta · okta
Okta Admin Functions Access Through Proxy
mediumDetects access to Okta admin functions through proxy.
okta · okta
Okta Admin Role Assigned to an User or Group
mediumDetects when an the Administrator role is assigned to an user or group.
okta · okta
Okta Admin Role Assignment Created
mediumDetects when a new admin role assignment is created. Which could be a sign of privilege escalation or persistence
okta · okta
Okta API Token Created
mediumDetects when a API token is created
okta · okta
Okta API Token Revoked
mediumDetects when a API Token is revoked.
okta · okta
Okta Application Modified or Deleted
mediumDetects when an application is modified or deleted.
okta · okta
Okta Application Sign-On Policy Modified or Deleted
mediumDetects when an application Sign-on Policy is modified or deleted.
okta · okta
Okta Identity Provider Created
mediumDetects when a new identity provider is created for Okta.
okta · okta
Okta MFA Reset or Deactivated
mediumDetects when an attempt at deactivating or resetting MFA.
okta · okta
Okta Network Zone Deactivated or Deleted
mediumDetects when an Network Zone is Deactivated or Deleted.
okta · okta
Okta Policy Rule Modified or Deleted
mediumDetects when an Policy Rule is Modified or Deleted.
okta · okta
Okta Security Threat Detected
mediumDetects when an security threat is detected in Okta.
okta · okta
Okta Session Impersonation Granted From Untrusted Domain
mediumDetects Okta session impersonation grant event where a user is granted the ability to impersonate another user's session. This event type "user.session.impersonation.grant" signifies that someone has been given temporary access to act on behalf of another user account. Threat actors may abuse this functionality to escalate privileges, access sensitive resources, or perform unauthorized actions while appearing to be the impersonated user. Legitimate use cases are typically limited to Okta support scenarios or authorized administrative troubleshooting.
okta · okta
Okta Unauthorized Access to App
mediumDetects when unauthorized access to app occurs.
okta · okta
Okta User Account Locked Out
mediumDetects when an user account is locked out.
okta · okta
Okta Password Health Report Query
lowDetects all activities against the endpoint "/reports/password-health/*" which should only be accessed via OKTA Admin Console UI. Use this rule to hunt for potential suspicious requests. Correlate this event with "admin console" login and alert on requests without any corresponding admin console login
okta · okta
Okta Policy Modified or Deleted
lowDetects when an Okta policy is modified or deleted.
okta · okta
New Okta User Created
informationalDetects new user account creation
okta · okta