Vendor: Okta

June 14, 2023 · View on GitHub

Product: Okta Adaptive MFA

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
14655141414
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-creation
okta-account-creation

account-enabled
okta-account-enabled

account-lockout
json-okta-account-lockout
cef-okta-logs-app-activity

account-password-change
okta-account-password-change

account-password-reset
cef-okta-account-password-reset
cef-okta-account-unlocked

app-activity
okta-app-activity
okta-app-activity-ad
s-okta-app-activity
okta-app-activity-1
cef-okta-app-activity
q-okta-app-activity
cef-okta-logs-app-activity

app-login
okta-app-login
s-okta-app-login
u-okta-app-login
q-okta-app-login-2
q-okta-app-login-3
q-okta-app-login-1
okta-app-login-1
s-okta-app-login-4
q-okta-app-login-6
s-okta-app-login-5
q-okta-app-login-4
s-okta-app-login-3
q-okta-app-login-5
q-okta-app-login
cef-okta-app-login
okta-app-activity
s-okta-app-activity
okta-app-activity-1
cef-okta-app-activity
cef-okta-app-login-1
q-okta-app-activity
cef-okta-logs-app-activity
json-okta-app-login
json-okta-app-login-1

authentication-failed
json-okta-authentication-failed-4
json-okta-authentication-failed-5
json-okta-authentication-failed-3

authentication-successful
json-okta-authentication-success
cef-okta-logs-authentication
s-okta-app-login-2
s-okta-app-login-1

failed-app-login
json-okta-failed-app-login-1
json-okta-failed-app-login-2
q-okta-failed-app-login-1
q-okta-failed-app-login-2
okta-failed-app-login
q-okta-failed-app-login
u-okta-failed-app-login
s-okta-failed-app-login
cef-okta-app-activity
s-okta-failed-login-4
cef-okta-app-login-1
q-okta-app-activity
json-okta-failed-app-login-5
cef-okta-logs-authentication
json-okta-failed-app-login-6
json-okta-failed-app-login-4
cef-okta-logs-app-activity

member-added
json-okta-member-added
cef-okta-member-added

member-removed
okta-member-removed
T1078 - Valid Accounts
T1110 - Brute Force
T1133 - External Remote Services
  • 16 Rules
  • 4 Models
Account Manipulationaccount-creation
okta-account-creation

account-password-change
okta-account-password-change

account-password-reset
cef-okta-account-password-reset
cef-okta-account-unlocked

app-activity
okta-app-activity
okta-app-activity-ad
s-okta-app-activity
okta-app-activity-1
cef-okta-app-activity
q-okta-app-activity
cef-okta-logs-app-activity

member-added
json-okta-member-added
cef-okta-member-added

member-removed
okta-member-removed
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
T1136 - Create Account
T1136.001 - Create Account: Create: Local Account
T1136.002 - T1136.002
  • 46 Rules
  • 19 Models
Brute Force Attackaccount-lockout
json-okta-account-lockout
cef-okta-logs-app-activity
T1110 - Brute Force
  • 1 Rules
Data Leakapp-activity
okta-app-activity
okta-app-activity-ad
s-okta-app-activity
okta-app-activity-1
cef-okta-app-activity
q-okta-app-activity
cef-okta-logs-app-activity
T1114.003 - Email Collection: Email Forwarding Rule
  • 3 Rules
Privilege Escalationapp-activity
okta-app-activity
okta-app-activity-ad
s-okta-app-activity
okta-app-activity-1
cef-okta-app-activity
q-okta-app-activity
cef-okta-logs-app-activity
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 3 Rules
  • 1 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

Create Account

External Remote Services

Valid Accounts

Account Manipulation

Create Account: Create: Local Account

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Exploitation for Privilege Escalation

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Obfuscated Files or Information

Brute Force

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Proxy