Skip to content

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.

Series

Investigating an Okta tenant

6 posts in this series. Read them in order or jump to any one.

  1. Okta Compromise Investigation Guide for Responders

    How to investigate a suspected Okta compromise from the System Log: scope, the eventTypes that matter, the attack chain step by step, and what to contain first.

  2. How to Export the Okta System Log (API, CSV, SIEM)

    Export the Okta System Log for an investigation: Admin Console CSV, /api/v1/logs with correct pagination, Log Streaming, SIEM exports and the traps to avoid.

  3. Okta System Log Analysis, Step by Step (Free Tool)

    Analyze an Okta System Log export in your browser: load the files, read the verdict and findings, pivot on users, IPs and sessions, and export the timeline.

  4. Okta eventType List: The Events Responders Need

    The Okta System Log eventTypes that matter in an incident, grouped by attack stage, with the fields to read and the Classic vs Identity Engine differences.

  5. Okta Incident Timeline Example: A Fictional Walkthrough

    A fictional Okta intrusion read event by event: helpdesk reset, attacker factor, Super Admin grant, rogue IdP and AWS access, with the analyzer's findings.

  6. Okta Detection False Positives: VPNs, Mobile, Tuning

    Why Okta identity detections misfire on corporate VPNs, mobile networks and helpdesk work, what the analyzer cannot see, and how to verify each finding.

All posts in this series

How to investigate a suspected Okta compromise from the System Log: scope, the eventTypes that matter, the attack chain step by step, and what to contain first.
Export the Okta System Log for an investigation: Admin Console CSV, /api/v1/logs with correct pagination, Log Streaming, SIEM exports and the traps to avoid.
Analyze an Okta System Log export in your browser: load the files, read the verdict and findings, pivot on users, IPs and sessions, and export the timeline.
The Okta System Log eventTypes that matter in an incident, grouped by attack stage, with the fields to read and the Classic vs Identity Engine differences.
A fictional Okta intrusion read event by event: helpdesk reset, attacker factor, Super Admin grant, rogue IdP and AWS access, with the analyzer's findings.
Why Okta identity detections misfire on corporate VPNs, mobile networks and helpdesk work, what the analyzer cannot see, and how to verify each finding.

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.