Analytics BIOC Informational

Okta API Token Created

A user created a new API token in Okta.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Okta Audit Log
ATT&CK tactics: Privilege Escalation (TA0004) Execution (TA0002) Persistence (TA0003)
ATT&CK techniques: Access Token Manipulation: Make and Impersonate Token (T1134.003) Command and Scripting Interpreter: Cloud API (T1059.009) Account Manipulation: Additional Cloud Credentials (T1098.001)
Detector tags: Okta Audit Analytics
Attacker's goals:

An attacker's goal is to gain unauthorized access, compromise user accounts, and perform malicious actions within an organization's systems, potentially leading to data breaches, account takeovers, and the escalation of privileges.

Investigative actions:

Review the actions taken by the user that created the token. Follow the operations made using this API token by the ID token. Contact the user who created the API token and ensure that the API token is needed.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • An Okta API token was generated with suspicious characteristics Low (parent: Informational)