Analytics BIOC Informational

A user modified an Okta network zone

An Okta network zone was modified by a user.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Okta Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses (T1562) Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)
Detector tags: Okta Audit Analytics
Attacker's goals:

An attacker may attempt to modify an Okta network zone to weaken an organization's security controls.

Investigative actions:

Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other network zones have been changed or removed.

Test period:
N/A (single event)
Deduplication:
2 Days
2 variations:
  • The user has made an unusual modification to the Okta Network zone Medium (parent: Informational)
  • A user modified an Okta network zone with suspicious characteristics Low (parent: Informational)