Rare MFA Operations (Okta)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


MFA prevents credential compromise. This query checks for rare MFA operations like deactivation, update, reset, and bypass attempts often used by adversaries to compromise networks/accounts.

Attribute Value
Type Hunting Query
Solution Okta Single Sign-On
ID 18667b4a-18e5-4982-ba75-92ace62bc79c
Tactics Persistence
Techniques T1098
Required Connectors OktaSSO, OktaSSOv2
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
OktaV2_CL ? ?
Okta_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Okta Single Sign-On