Skip to content

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.

Series

Okta identity attack patterns

6 posts in this series. Read them in order or jump to any one.

  1. MFA Fatigue Attack Detection in Okta System Logs

    Detect MFA fatigue (push bombing) in the Okta System Log: the Classic and Identity Engine eventTypes, a workable threshold, false positives, and what to fix.

  2. Helpdesk Social Engineering and MFA Resets in Okta

    How helpdesk social engineering turns into an Okta MFA reset and account takeover, the reset-then-enroll sequence in the logs, and how to tell it from support.

  3. Okta Session Hijacking: Detect Stolen Session Cookies

    Detect Okta session hijacking in the System Log: one externalSessionId used from several ASNs or browsers, roaming events, and ruling out VPN and mobile noise.

  4. Okta Cross-Tenant Impersonation: Rogue IdP Persistence

    How attackers add an inbound identity provider to an Okta org to sign in as any user, the System Log events that expose it, and how to remove the backdoor.

  5. Okta Super Admin Role and API Token Abuse in the Logs

    Find Okta admin role grants, API tokens, weakened policies and support impersonation in the System Log, and remove the persistence an attacker left behind.

  6. Okta Password Spraying Detection in the System Log

    Detect password spraying, brute force and credential stuffing against Okta: failure patterns per IP and user, ThreatInsight events, and the success to hunt.

All posts in this series

Detect MFA fatigue (push bombing) in the Okta System Log: the Classic and Identity Engine eventTypes, a workable threshold, false positives, and what to fix.
How helpdesk social engineering turns into an Okta MFA reset and account takeover, the reset-then-enroll sequence in the logs, and how to tell it from support.
Detect Okta session hijacking in the System Log: one externalSessionId used from several ASNs or browsers, roaming events, and ruling out VPN and mobile noise.
How attackers add an inbound identity provider to an Okta org to sign in as any user, the System Log events that expose it, and how to remove the backdoor.
Find Okta admin role grants, API tokens, weakened policies and support impersonation in the System Log, and remove the persistence an attacker left behind.
Detect password spraying, brute force and credential stuffing against Okta: failure patterns per IP and user, ThreatInsight events, and the success to hunt.

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.