Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Okta Reported Threat Detected Informational Identity Threat Module, SaaS Threat Detection 1 variation

    Okta Threat Insight Reported Threat Detected.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    3 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: Okta Audit Log
    Detector tags: Okta Audit Analytics
    Attacker's goals: An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.
    Investigative actions: Investigate the original events that were reported as suspicious. Investigate additional alerts that are activated based on the IP address. Follow further actions done by the ip.

    Variations

    Okta detected multiple threats from the same IP along with other suspicious characteristics

    Low overridden

    Okta Threat Insight Reported Threat Detected. overridden