Analytics
Informational
✕
Okta account reset password attempt
A user used a weak factor to reset their Okta password.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Okta Audit Log
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078)
Detector tags: Okta Audit Analytics
Attacker's goals:
The attacker might deceive the victim into resetting their password, a common tactic in account takeover schemes.
Investigative actions:
Monitor the user account for indications of compromise, such as irregular login patterns or atypical activities. Reach out to the user to confirm the legitimacy of the recent password reset activity. Examine the IP address and assess its reputation. Continue monitoring the account for any subsequent actions that may indicate suspicious behavior.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- Suspicious Okta account reset password attempt Low (parent: Informational)