Glossary
Okta ThreatInsight
Okta's service that flags and can block authentication requests from IP addresses seen in credential-based attacks across Okta customers.
Okta ThreatInsight evaluates the source IP of authentication requests against activity Okta observes across its customer base and flags addresses associated with credential-based attacks such as password spraying. It can be off, log only, or log and enforce security based on threat level (Okta Help Center). In the System Log, security.threat.detected records a request from an IP classed as malicious, security.attack.start records that the org is under attack, and debugContext.debugData.threatSuspected marks individual events. See password spraying detection.