Okta 2023 Breach Indicator Of Compromise
Detects new user account creation or activation with specific names related to the Okta Support System 2023 breach. This rule can be enhanced by filtering out known and legitimate username used in your environnement.
Detection logic
selection
eventType:
- user.lifecycle.create
- user.lifecycle.activate
target.displayName|contains: svc_network_backupCondition
selectionRaw YAML
title: Okta 2023 Breach Indicator Of Compromise
id: 00a8e92a-776b-425f-80f2-82d8f8fab2e5
status: test
description: |
Detects new user account creation or activation with specific names related to the Okta Support System 2023 breach.
This rule can be enhanced by filtering out known and legitimate username used in your environnement.
author: Muhammad Faisal (@faisalusuf)
date: 2023-10-25
modified: 2026-04-27
references:
- https://www.beyondtrust.com/blog/entry/okta-support-unit-breach
- https://developer.okta.com/docs/reference/api/event-types/
tags:
- attack.credential-access
- detection.emerging-threats
logsource:
service: okta
product: okta
detection:
selection:
eventType:
- 'user.lifecycle.create'
- 'user.lifecycle.activate'
target.displayName|contains: 'svc_network_backup'
condition: selection
falsepositives:
- Unknown
level: mediumFalse positives
- Unknown