Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Suspicious SSO authentication Informational Identity Analytics 2 variations

    A suspicious SSO authentication was made by a user.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts (T1078)
    Required data: Okta
    Attacker's goals: Achieve initial access to a company's resources.
    Investigative actions: See whether this was a legitimate action. Review the external IP/domain involved in the alert. Contact the user whose account is being accessed and verify that they are actually attempting to log in. Check if the login attempt is coming from an unfamiliar location or device. Look for unusual login patterns, such as login attempts at odd hours. Monitor the user's account for further unusual activity.

    Variations

    Successful SSO authentication with suspicious characteristics

    Medium overridden

    A user successfully accessed SSO with some suspicious characteristics that flagged this login attempt as a suspicious login. overridden

    SSO authentication attempt with suspicious characteristics

    Low overridden

    A user accessed SSO with some suspicious characteristics that flagged this login attempt as a suspicious login. overridden