惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
News and Events Feed by Topic
T
The Exploit Database - CXSecurity.com
P
Palo Alto Networks Blog
T
Threat Research - Cisco Blogs
Cloudbric
Cloudbric
Recent Commits to openclaw:main
Recent Commits to openclaw:main
I
Intezer
Attack and Defense Labs
Attack and Defense Labs
P
Privacy International News Feed
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
L
Lohrmann on Cybersecurity
C
Cybersecurity and Infrastructure Security Agency CISA
V2EX - 技术
V2EX - 技术
AWS News Blog
AWS News Blog
O
OpenAI News
L
LINUX DO - 最新话题
N
News | PayPal Newsroom
PCI Perspectives
PCI Perspectives
www.infosecurity-magazine.com
www.infosecurity-magazine.com
T
Troy Hunt's Blog
Latest news
Latest news
D
Darknet – Hacking Tools, Hacker News & Cyber Security
A
Arctic Wolf
Spread Privacy
Spread Privacy
G
GRAHAM CLULEY
T
Tor Project blog
博客园_首页
Know Your Adversary
Know Your Adversary
有赞技术团队
有赞技术团队
S
Secure Thoughts
美团技术团队
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
T
Tailwind CSS Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
V
Visual Studio Blog
J
Java Code Geeks
Cisco Talos Blog
Cisco Talos Blog
Schneier on Security
Schneier on Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Security Affairs
Jina AI
Jina AI
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
宝玉的分享
宝玉的分享
量子位
Last Week in AI
Last Week in AI
月光博客
月光博客
罗磊的独立博客
S
SegmentFault 最新的问题

Okta Security RSS Feed

OpenSSL HollowByte: A DoS Hiding in 11 Bytes Datadog and Okta Combine for New Customer Detections Detecting OpenClaw at Sign-In Okta Hardening Guide Updated to Secure Non-Human Identities Okta Pooled Security Audits: a One-Year Retrospective Account Recovery, without Password Resets Okta’s Response to React2Shell Uncloaking VoidProxy: a Novel and Evasive Phishing-as-a-Service Framework Attackers Target Hotelier Accounts in Malvertising and Phishing Campaign Using Auth0 Logs for Proactive Threat Detection Controlling Cross-App Data Sprawl in Google Workspace How this ClickFix campaign leads to Redline Stealer Paving the Path: Pooled Audits with Okta Security Building Confidence in Support Comms with Caller Verify at Okta Enabling ISO/IEC 27001:2022 Compliance with Okta Okta’s Secure by Design Pledge - One Year On Leveraging Okta System Logs for Proactive Threat Detection Enhancing Customer Trust Through a Comprehensive Audit Program Okta's new Security Technical Implementation Guide (STIG) A Guide to DORA Compliance with Okta How AI services power the DPRK’s IT contracting scams Detect and Prevent Cross Device Authentication How Responsible Disclosures are Shaping a Safer Cyberspace Cybersecurity’s Next Gen Next.js CVE-2025-29927 CSO Conversations: Matthew Hansen, Regional CSO of Americas West Empowering Security with Customer Trust Solutions Putting Security First with Secure Development One trick finds the root of any Okta troubles CSO Conversations: Stephen McDermid, Regional CSO of EMEA Content-Security-Policy in a Complex Environment CSO Conversations: Keiko Itakura, Regional CSO of Japan How Okta Embraces Identity Verification Using Persona CSO Conversations: Matt Immler, Regional CSO of Americas East Raising the Bar for our Industry with IPSIE Cyber-Safety over the Holidays Okta Social Engineering Impersonation Report - Response and Recommendation Five Reasons to Upgrade your Org to Okta Identity Engine Okta’s Ongoing Commitment to Secure By Design Unveiling the Essence of the Security Customer Trust Function Security Education Through the Art of Storytelling Seven Ways to Reduce Super Admins in Okta The Case for Zero Standing Privileges FastPass: The battle-hardened authenticator Detecting Cross-Origin Authentication Credential Stuffing Attacks How to Block Anonymizing Services using Okta Why Cyber-heroes need a Zero Trust CAEP! Okta Verify Vulnerability Disclosure Report - Response and Remediation Defensive Domain Registration is a Mug’s Game Protecting Administrative Sessions in Okta How to Secure the SaaS Apps of the Future Okta October 2023 Security Incident Investigation Closure October Customer Support Security Incident - Update and Recommended Actions Unauthorized Access to Okta's Support Case Management System: Root Cause and Remediation Tracking Unauthorized Access to Okta's Support System Go “Secure by Default” With Custom Admin Roles for IT support staff Cross-Tenant Impersonation: Prevention and Detection BYO Telephony and the future of SMS at Okta Saying “No Thanks” to nOAuth An Unexpected Endorsement for WebAuthn Social Engineering is Getting More Extreme, but the Fixes Can Be Simple Study up on Okta Logs for Splunk’s Boss of the SOC! Keeping Phishing Adversaries Out of the Middle Using Workflows to Respond to Anomalous Push Requests Okta and Splunk Combine to Detect Common Attacks Setting the Right Levels of Assurance for Zero Trust Catch-All's and Canary Rules User Sign-in and Recovery Events in the Okta System Log Okta Code Repositories Detecting Real-Time Phishing Attacks Detecting Real-Time Phishing Attacks Okta’s Response to OpenSSL Security Update Monitoring for Abuse of Administrative Privileges System Log: a Window into Supporting the Okta Cloud The Human Factor in Phishing Resistance Auth0 Code Repository Archives From 2020 and Earlier Phishing Resistance and Why it Matters Detecting Scatter Swine: Insights into a Relentless Phishing Campaign Defending against Session Hijacking Unlocking the Mystery of 700+ Okta System Log Events Official Okta Statement on LAPSUS$ Claims Protection, without perimeters We (still) need to talk about RDP Just How Risky is Legacy Authentication?
Telling More Okta Detection Stories with Google Chronicle
Defensive Cyber Operations · 2023-08-02 · via Okta Security RSS Feed

Robust protection comes from layers, and many of you are already familiar with the Swiss Cheese Model. Simply stated, even when you're confident in your primary controls, that confidence only grows with each additional layer added. Because who wants to have a defense that’s built around a single slice of sad cheese, wrapped in a pitiful film of plastic? No thanks, we’ll take that sturdy block of Swiss each and every time.

Of course, given how thin most security teams are spread, robust layering is often easier said than done. Not every security team has the luxury of dedicated Detection Engineers to craft, research and develop custom logic to catch threat actor activity, and not every security team has the time and skill to synthesize and recreate our logic in other SIEM platforms. With this in mind, Okta Security recently published a number of our bespoke detections.

“But,” quoth the game show hosts, “ that’s not all!” Today we’re excited to share that Chronicle and Okta have been collaborating to help these detections reach an even wider audience. And this time around, the Chronicle team threw a few extra slices of cheese on top!

Not only did they rewrite these detections for their environment, they also did their own research and wrote additional detections. You can read more about each of them over at Chronicle’s blog. We’ve described them below too.

To channel the words of Oprah, “You get a new detection, and you get a new detection, and you get a new detection!”

Okta Phishing Detection with FastPass Origin Check

ID

T1566

Technique

Phishing

Chronicle identifier

okta_phishing_detection_with_fastpass_origin_check

Description

Okta provides a platform detection for when a user enrolled in FastPass fails to authenticate via a real-time AiTM phishing proxy.

Okta Reference

Detecting Real-Time Phishing Attacks

Okta System Log Query

eventType eq "user.authentication.auth_via_mfa" AND result eq "FAILURE" AND outcome.reason eq "FastPass declined phishing attempt"

Successful MFA After Multiple Failures

Repeated MFA Rejections by User

ID

T1110

Technique

Brute Force

Chronicle identifier

okta_user_rejected_multiple_push_notifications

Description

NEW: Detects when an Okta user rejects more than 2 Push notifications in a 10 minute window.

Okta Reference

Using Workflows to Respond to Anomalous Push Requests

Okta System Log Query

Okta Identity Engine

eventType eq "user.authentication.auth_via_mfa" AND outcome.result="FAILURE" and outcome.reason="INVALID_CREDENTIALS" and debugContext.debugData.factor eq "OKTA_VERIFY_PUSH"

Okta Classic Engine

eventType eq  "user.mfa.okta_verify.deny_push"

Failed Number Challenge

Mismatch Between Source and Response for Verify Push Request

Multiple Failed Users with Invalid Credentials from the same IP

User Reported Suspicious Activity

ID

T1078

Technique

Valid Account

Chronicle identifier

okta_user_suspicious_activity_reported

Description

NEW: An Okta user reports suspicious activity in response to an end user security notification.

Okta Reference

Suspicious Activity Reporting

Okta System Log Query

eventType eq "user.account.report_suspicious_activity_by_enduser"

Multiple Failed Requests to Access Okta Applications

ThreatInsight Alert: Suspected Brute Force

ID

T1110.001

Technique

Brute Force: Password Guessing

Chronicle identifier

okta_threatinsight_suspected_brute_force_attack

Description

NEW: Okta ThreatInsight detects multiple login failures from the same IP across one or more Okta orgs

Okta Reference

System Log events for Okta ThreatInsight

Okta System Log Query

eventType eq "security.threat.detected" and outcome.reason eq "Login Failures"

ThreatInsight Alert: Suspected Targeted Brute Force

ID

T1110

Technique

Brute Force

Chronicle identifier

okta_threatinsight_targeted_brute_force_attack

Description

NEW: Okta ThreatInsight detects access requests from known malicious IPs targeting a specific org.

Okta Reference

System Log events for Okta ThreatInsight

Okta System Log Query

eventType eq "security.attack.start"

ThreatInsight Alert: Login Failure with High Unknown Users

ID

T1110.004

Technique

Brute Force: Credential Stuffing

Chronicle identifier

okta_threatinsight_login_failure_with_high_unknown_users

Description

Okta's ThreatInsight can identify multiple login failures with high unknown users count from the same IP across one or more Okta orgs.

Okta Reference

System Log events for Okta ThreatInsight

Okta System Log Query

eventType eq "security.threat.detected" AND outcome.reason co "Login failures with high unknown users count"

ThreatInsight Alert: Suspected Password Spray Attack

ID

T1110.003

Technique

Brute Force: Password Spraying

Chronicle identifier

okta_threatinsight_suspected_password_spray_attack

Description

Okta's ThreatInsight can identify Password Spray attacks.

Okta Reference

System Log events for Okta ThreatInsight

Okta System Log Query

eventType eq "security.threat.detected" and outcome.reason eq "Password Spray"

Successful Login Evaluated as High Risk

ID

T1078

Technique

Valid Accounts

Chronicle identifier

okta_successful_high_risk_user_logins

Description

NEW: Detects successfully authenticated user logins based on Okta's Behavior Detection pattern analysis.

Okta Reference

Behavior Detection System Log events

Okta System Log Query

outcome.result eq "SUCCESS" and debugContext.debugData.risk co "HIGH"

Okta User Account Lockout

ID

T1078

Technique

Valid Accounts

Chronicle identifier

okta_user_account_lockout

Description

NEW: Detects when a user's account is locked out or a user account has reached the lockout limit.

Okta Reference

How Adaptive MFA Helps Mitigate Brute Force Attacks

Okta System Log Query

eventType eq "user.account.lock"

New Okta API Token Created

ID

T1078 

Technique

Valid Accounts

Chronicle Identifier

okta_new_api_token_created

Description

NEW: Detects when a new API token is created.

Okta Reference

Tokens

Okta System Log Query

eventType eq "system.api_token.create"

Out of Hours Successful Authentication

User Logins from Multiple Cities

We found this exercise to be fulfilling. Writing YARA-L queries is new to us, but they have been super easy to read and collaborate on. Even if you’re not a Chronicle customer, you might find it valuable to read the detection logic in Chronicle to frame your thinking about how you might go about detecting these types of threats.

What’s next?

Once we’re happy with our detections, phishing resistant factors and other control slices; where should we invest our energy next? I’d suggest considering what an adversary might now need to do for persistence and lateral movement. Perhaps they could socially engineer a new factor, a managed device or even a whole new account?

Best get thinking about how you’d detect:

  • User factors added or modified (user.mfa.factor*)

  • New users created (user.lifecycle.create)

  • Devices added to MDM

  • Remote Monitoring and Management tool installation or execution

  • VM installation on workstations

  • Duplicate hostnames

Gouda luck!

The Defensive Cyber Operations (DCO) team is responsible for detecting and responding to cyber threats that impact Okta or our customers via the Okta platform. Our intelligence-driven capability identifies the adversaries most likely to impact Okta and our customers, and prioritises our defensive capabilities based on the threats most likely to be realised.