Series
Okta identity attack patterns
6 posts in this series. Read them in order or jump to any one.
- MFA Fatigue Attack Detection in Okta System Logs
Detect MFA fatigue (push bombing) in the Okta System Log: the Classic and Identity Engine eventTypes, a workable threshold, false positives, and what to fix.
- Helpdesk Social Engineering and MFA Resets in Okta
How helpdesk social engineering turns into an Okta MFA reset and account takeover, the reset-then-enroll sequence in the logs, and how to tell it from support.
- Okta Session Hijacking: Detect Stolen Session Cookies
Detect Okta session hijacking in the System Log: one externalSessionId used from several ASNs or browsers, roaming events, and ruling out VPN and mobile noise.
- Okta Cross-Tenant Impersonation: Rogue IdP Persistence
How attackers add an inbound identity provider to an Okta org to sign in as any user, the System Log events that expose it, and how to remove the backdoor.
- Okta Super Admin Role and API Token Abuse in the Logs
Find Okta admin role grants, API tokens, weakened policies and support impersonation in the System Log, and remove the persistence an attacker left behind.
- Okta Password Spraying Detection in the System Log
Detect password spraying, brute force and credential stuffing against Okta: failure patterns per IP and user, ThreatInsight events, and the success to hunt.