High-Risk Admin Activity

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


The Okta risk engine auto-assigns risk levels to each login attempt. This query identifies admin operations originating from events associated with high-risk profiles.

Attribute Value
Type Analytic Rule
Solution Okta Single Sign-On
ID 9f82a735-ae43-4c03-afb4-d5d153e1ace1
Severity Medium
Status Available
Kind Scheduled
Tactics Persistence
Techniques T1098
Required Connectors OktaSSO, OktaSSOv2
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
OktaV2_CL ? ?
Okta_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Okta Single Sign-On