Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0001 ✕

Download CSV Show ATT&CK heatmap
  • Okta device assignment Informational Identity Threat Module, SaaS Threat Detection 1 variation

    A device was assigned as an Okta MFA device to a user.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    6 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: Okta Audit Log
    Detector tags: Okta Audit Analytics
    Attacker's goals: For purposes of maintaining persistence, an attacker could potentially register his device with various accounts that have been compromised.
    Investigative actions: Confirm that the device assignments were intentionally made by the users and are legitimate. Examine the IP address and assess its reputation. Continue monitoring the accounts for any subsequent actions that may indicate suspicious behavior.

    Variations

    A suspicious assignment of a mobile device to multiple users

    Low overridden

    A single device is being used as an Okta MFA device by multiple users. overridden