Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapOkta Reported Threat Detected Informational Identity Threat Module, SaaS Threat Detection 1 variation
Okta Threat Insight Reported Threat Detected.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 3 Hours
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts (T1078)Required data: Okta Audit LogDetector tags: Okta Audit AnalyticsAttacker's goals: An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.Investigative actions: Investigate the original events that were reported as suspicious. Investigate additional alerts that are activated based on the IP address. Follow further actions done by the ip.Variations
Okta detected multiple threats from the same IP along with other suspicious characteristics
Low overridden
Okta Threat Insight Reported Threat Detected. overridden