Analytics
Informational
✕
A user observed and reported unusual activity in Okta
A user observed and reported unusual activity in Okta.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Okta Audit Log
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078)
Detector tags: Okta Audit Analytics
Attacker's goals:
An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.
Investigative actions:
Investigate the original event that was reported as suspicious. Contact the user and understand why he reported the activity as suspicious. Look for signs that the user account is compromised (e.g. abnormal logins, unusual activity). Follow further actions done by the account.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
2 variations:
- Multiple users have reported the same suspicious activity Medium (parent: Informational)
- Unusual activity in Okta was reported by a user along with suspicious characteristics Low (parent: Informational)