Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • A user observed and reported unusual activity in Okta Informational Identity Threat Module, SaaS Threat Detection 2 variations

    A user observed and reported unusual activity in Okta.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: Okta Audit Log
    Detector tags: Okta Audit Analytics
    Attacker's goals: An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.
    Investigative actions: Investigate the original event that was reported as suspicious. Contact the user and understand why he reported the activity as suspicious. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account.

    Variations

    Multiple users have reported the same suspicious activity

    Medium overridden

    Unusual activity in Okta reported about an IP not linked to an EDR agent, the operation is rare and flagged by multiple users. overridden

    Unusual activity in Okta was reported by a user along with suspicious characteristics

    Low overridden

    A user observed and reported unusual activity in Okta. overridden