Analytics Informational

Okta Reported Threat Detected

Okta Threat Insight Reported Threat Detected.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Okta Audit Log
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078)
Detector tags: Okta Audit Analytics
Attacker's goals:

An attacker tries infiltrating an Okta account to gain unauthorized access to valuable resources.

Investigative actions:

Investigate the original events that were reported as suspicious. Investigate additional alerts that are activated based on the IP address. Follow further actions done by the ip.

Test period:
3 Hours
Deduplication:
1 Day
1 variation:
  • Okta detected multiple threats from the same IP along with other suspicious characteristics Low (parent: Informational)