Analytics BIOC
Informational
✕
Suspicious SSO authentication
A suspicious SSO authentication was made by a user.
- Module:
- Identity Analytics
- Data source:
- Okta
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078)
Attacker's goals:
Achieve initial access to a company's resources.
Investigative actions:
See whether this was a legitimate action. Review the external IP/domain involved in the alert. Contact the user whose account is being accessed and verify that they are actually attempting to log in. Check if the login attempt is coming from an unfamiliar location or device. Look for unusual login patterns, such as login attempts at odd hours. Monitor the user's account for further unusual activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Successful SSO authentication with suspicious characteristics Medium (parent: Informational)
- SSO authentication attempt with suspicious characteristics Low (parent: Informational)