Analytics BIOC
Informational
✕
Potential Okta access limit breach
A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Okta Audit Log
ATT&CK tactics: Collection (TA0009) Initial Access (TA0001)
ATT&CK techniques: Automated Collection (T1119) Valid Accounts (T1078)
Detector tags: Okta Audit Analytics
Attacker's goals:
An adversary may attempt to use a compromised account in an unusual way to harvest as much data as possible, which could result in exceeding the access limit policy.
Investigative actions:
Reach out to the user responsible for the alert to confirm the legitimacy of the activity. Examine the user's actions preceding and following the activation of the alert. Investigate abnormal logins, reported suspicious activities, new processes run, and recent configuration changes for any indicators of potential compromise. Assess the reputation of the IP address along with that of the Autonomous System Number (ASN).
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- A breach in access limits within Okta, accompanied by suspicious characteristics Low (parent: Informational)