Analytics BIOC
Informational
✕
A user modified an Okta policy rule
An Okta policy rule was modified by a user, suggesting a potential compromise of the account.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Okta Audit Log
ATT&CK tactics: Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Impair Defenses (T1562) Domain or Tenant Policy Modification (T1484) Modify Authentication Process (T1556)
Detector tags: Okta Audit Analytics
Attacker's goals:
An attacker may attempt to modify an Okta policy rule to weaken an organization's security controls.
Investigative actions:
Follow further actions done by the account. Verify that the configuration change was expected. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Investigate if any other security policies have been changed or removed.
- Test period:
- N/A (single event)
- Deduplication:
- 2 Days
1 variation:
- A user modified an Okta policy rule with suspicious characteristics Low (parent: Informational)