- AWS Console Sign-In NOT PRECEDED BY Okta Redirect
- A user has logged into the AWS console without authenticating via Okta. This rule requires AWS SSO via Okta and both log sources configured.
- Brute Force By IP
- An actor user was denied login access more times than the configured threshold.
- Brute Force By User
- An actor user was denied login access more times than the configured threshold.
- Impossible Travel for Login Action
- A user has subsequent logins from two geographic locations that are very far apart
- MFA Disabled
- Detects when Multi-Factor Authentication (MFA) is disabled
- Okta Admin Access Granted
- Audit instances of admin access granted in your okta tenant
- Okta Admin Role Assigned
- A user has been granted administrative privileges in Okta
- Okta AiTM Phishing Attempt Blocked by FastPass
- Okta FastPass detected a user targeted by attackers wielding real-time (AiTM) proxies.
- Okta API Key Created
- A user created an API Key in Okta
- Okta API Key Revoked
- A user has revoked an API Key in Okta
- Okta App Refresh Access Token Reuse
- When a client wants to renew an access token, it sends the refresh token with the access token request to the /token Okta endpoint.Okta validates the incoming refresh token, issues a new set of tokens and invalidates the refresh token that was passed with the initial request.This detection alerts when a previously used refresh token is used again with the token request
- Okta App Unauthorized Access Attempt
- Detects when a user is denied access to an Okta application
- Okta Cleartext Passwords Extracted via SCIM Application
- An application admin has extracted cleartext user passwords via SCIM app. Malcious actors can extract plaintext passwords by creating a SCIM application under their control and configuring it to sync passwords from Okta.
- Okta Group Admin Role Assigned
- Detect when an admin role is assigned to a group
- Okta HAR File IOCs
- Okta Identity Provider Created or Modified
- A new 3rd party Identity Provider has been created or modified. Attackers have been observed configuring a second Identity Provider to act as an "impersonation app" to access applications within the compromised Org on behalf of other users. This second Identity Provider, also controlled by the attacker, would act as a “source” IdP in an inbound federation relationship (sometimes called “Org2Org”) with the target.
- Okta Identity Provider Sign-in
- A user has signed in using a 3rd party Identity Provider. Attackers have been observed configuring a second Identity Provider to act as an "impersonation app" to access applications within the compromised Org on behalf of other users. This second Identity Provider, also controlled by the attacker, would act as a “source” IdP in an inbound federation relationship (sometimes called “Org2Org”) with the target. From this “source” IdP, the threat actor manipulated the username parameter for targeted users in the second “source” Identity Provider to match a real user in the compromised “target” Identity Provider. This provided the ability to Single sign-on (SSO) into applications in the target IdP as the targeted user. Do not use this rule if your organization uses legitimate 3rd-party Identity Providers.
- Okta Investigate MFA and Password resets
- Investigate Password and MFA resets for the last 7 days
- Okta Investigate Session ID Activity
- Search for activity related to a specific SessionID in Okta panther_logs.okta_systemlog
- Okta Investigate User Activity
- Audit user activity across your environment. Customize to filter on specific users, time ranges, etc
- Okta Login From CrowdStrike Unmanaged Device
- Okta Logins from an IP Address not found in CrowdStrike's AIP List
- Okta Login From CrowdStrike Unmanaged Device (crowdstrike_fdrevent table)
- Okta Logins from an IP Address not found in CrowdStrike's AIP List (crowdstrike_fdrevent table)
- Okta MFA Globally Disabled
- An admin user has disabled the MFA requirement for your Okta account
- Okta New Behaviors Acessing Admin Console
- New Behaviors Observed while Accessing Okta Admin Console. A user attempted to access the Okta Admin Console from a new device with a new IP.
- Okta Org2Org application created of modified
- An Okta Org2Org application has been created or modified. Okta's Org2Org applications instances are used to push and match users from one Okta organization to another. A malicious actor can add an Org2Org application instance and create a user in the source organization (controlled by the attacker) with the same identifier as a Super Administrator in the target organization.
- Okta Password Accessed
- User accessed another user's application password
- Okta Potentially Stolen Session
- This rule looks for the same session being used from two devices, indicating a compromised session token.
- Okta Rate Limits
- Potential DoS/Bruteforce attack or hitting limits (system degradation)
- Okta Sign-In from VPN Anonymizer
- A user is attempting to sign-in to Okta from a known VPN anonymizer. The threat actor would access the compromised account using anonymizing proxy services.
- Okta Support Access
- Show instances that Okta support was granted to your account
- Okta Support Access Granted
- An admin user has granted access to Okta Support to your account
- Okta Support Reset Credential
- A Password or MFA factor was reset by Okta Support
- Okta ThreatInsight Security Threat Detected
- Okta ThreatInsight identified request from potentially malicious IP address
- Okta User Account Locked
- An Okta user has locked their account.
- Okta User MFA Factor Suspend
- Suspend factor or authenticator enrollment method for user.
- Okta User MFA Own Reset
- User has reset one of their own MFA factors
- Okta User MFA Reset All
- All MFA factors have been reset for a user.
- Okta User Reported Suspicious Activity
- Suspicious Activity Reporting provides an end user with the option to report unrecognized activity from an account activity email notification.This detection alerts when a user marks the raised activity as suspicious.
- Okta Username Above 52 Characters Security Advisory
- On October 30, 2024, a vulnerability was internally identified in generating the cache key for AD/LDAP DelAuth. The Bcrypt algorithm was used to generate the cache key where we hash a combined string of userId + username + password. Under a specific set of conditions, listed below, this could allow users to authenticate by providing the username with the stored cache key of a previous successful authentication. Customers meeting the pre-conditions should investigate their Okta System Log for unexpected authentications from usernames greater than 52 characters between the period of July 23rd, 2024 to October 30th, 2024. https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/
- Sign In from Rogue State
- Detects when an entity signs in from a nation associated with cyber attacks
This repository was archived by the owner on Sep 16, 2026. It is now read-only.