Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0001 ✕
Download CSV Show ATT&CK heatmapSuspicious SSO authentication Informational Identity Analytics 2 variations
A suspicious SSO authentication was made by a user.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts (T1078)Required data: OktaAttacker's goals: Achieve initial access to a company's resources.Investigative actions: See whether this was a legitimate action. Review the external IP/domain involved in the alert. Contact the user whose account is being accessed and verify that they are actually attempting to log in. Check if the login attempt is coming from an unfamiliar location or device. Look for unusual login patterns, such as login attempts at odd hours. Monitor the user's account for further unusual activity.Variations
Successful SSO authentication with suspicious characteristics
Medium overridden
A user successfully accessed SSO with some suspicious characteristics that flagged this login attempt as a suspicious login. overridden
SSO authentication attempt with suspicious characteristics
Low overridden
A user accessed SSO with some suspicious characteristics that flagged this login attempt as a suspicious login. overridden