Series
Investigating an Okta tenant
6 posts in this series. Read them in order or jump to any one.
- Okta Compromise Investigation Guide for Responders
How to investigate a suspected Okta compromise from the System Log: scope, the eventTypes that matter, the attack chain step by step, and what to contain first.
- How to Export the Okta System Log (API, CSV, SIEM)
Export the Okta System Log for an investigation: Admin Console CSV, /api/v1/logs with correct pagination, Log Streaming, SIEM exports and the traps to avoid.
- Okta System Log Analysis, Step by Step (Free Tool)
Analyze an Okta System Log export in your browser: load the files, read the verdict and findings, pivot on users, IPs and sessions, and export the timeline.
- Okta eventType List: The Events Responders Need
The Okta System Log eventTypes that matter in an incident, grouped by attack stage, with the fields to read and the Classic vs Identity Engine differences.
- Okta Incident Timeline Example: A Fictional Walkthrough
A fictional Okta intrusion read event by event: helpdesk reset, attacker factor, Super Admin grant, rogue IdP and AWS access, with the analyzer's findings.
- Okta Detection False Positives: VPNs, Mobile, Tuning
Why Okta identity detections misfire on corporate VPNs, mobile networks and helpdesk work, what the analyzer cannot see, and how to verify each finding.