Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • A user attempted to bypass Okta MFA Low Identity Threat Module, SaaS Threat Detection 1 variation

    A user may have attempted to bypass Okta MFA.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Modify Authentication Process (T1556) Multi-Factor Authentication Request Generation (T1621)
    Required data: Okta Audit Log
    Detector tags: Okta Audit Analytics
    Attacker's goals: An attacker is attempting to gain access to an account secured with MFA.
    Investigative actions: Contact the user who attempted to bypass MFA and ensure the request was legitimate. Check if the user successfully authenticated after the event.

    Variations

    A successful bypass of Okta MFA

    Low overridden

    Suspicious MFA bypass attempt in Okta. overridden