Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0003 ✕ technique: T1078 ✕
Download CSV Show ATT&CK heatmapOkta device assignment Informational Identity Threat Module, SaaS Threat Detection 1 variation
A device was assigned as an Okta MFA device to a user.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 6 Hours
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003)ATT&CK techniques: Valid Accounts (T1078)Required data: Okta Audit LogDetector tags: Okta Audit AnalyticsAttacker's goals: For purposes of maintaining persistence, an attacker could potentially register his device with various accounts that have been compromised.Investigative actions: Confirm that the device assignments were intentionally made by the users and are legitimate. Examine the IP address and assess its reputation. Continue monitoring the accounts for any subsequent actions that may indicate suspicious behavior.Variations
A suspicious assignment of a mobile device to multiple users
Low overridden
A single device is being used as an Okta MFA device by multiple users. overridden