Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • A user modified an Okta network zone Informational Identity Threat Module, SaaS Threat Detection 2 variations

    An Okta network zone was modified by a user.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    2 Days
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses (T1562) Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)
    Required data: Okta Audit Log
    Detector tags: Okta Audit Analytics
    Attacker's goals: An attacker may attempt to modify an Okta network zone to weaken an organization's security controls.
    Investigative actions: Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other network zones have been changed or removed.

    Variations

    The user has made an unusual modification to the Okta Network zone

    Medium overridden

    An atypical modification to the Okta Network zone has been performed by the user. overridden

    A user modified an Okta network zone with suspicious characteristics

    Low overridden

    An Okta network zone was modified by a user with suspicious characteristics. overridden