{"id":"a0b38b70-3cb5-484b-a4eb-c4d8e7bcc0a9","title":"Okta New Admin Console Behaviours","description":"Detects when Okta identifies new activity in the Admin Console.","author":"kelnage","status":"test","level":"high","date":"2023-09-07","modified":"2026-04-27","tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.stealth","attack.t1078.004"],"technique_ids":["T1078.004"],"logsource":{"product":"okta","service":"okta"},"falsepositives":["When an admin begins using the Admin Console and one of Okta's heuristics incorrectly identifies the behavior as being unusual."],"references":["https://developer.okta.com/docs/reference/api/system-log/","https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection"],"source_path":"rules/identity/okta/okta_new_behaviours_admin_console.yml","source_sha256":"512e67ffd19010bd80d88cf6af4525d1bdfb5f134e4f4978ae50db77d39883e3","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/identity/okta/okta_new_behaviours_admin_console.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Okta New Admin Console Behaviours\nid: a0b38b70-3cb5-484b-a4eb-c4d8e7bcc0a9\nstatus: test\ndescription: Detects when Okta identifies new activity in the Admin Console.\nreferences:\n    - https://developer.okta.com/docs/reference/api/system-log/\n    - https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection\nauthor: kelnage\ndate: 2023-09-07\nmodified: 2026-04-27\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.initial-access\n    - attack.stealth\n    - attack.t1078.004\nlogsource:\n    product: okta\n    service: okta\ndetection:\n    selection_event:\n        eventType: 'policy.evaluate_sign_on'\n        target.displayName: 'Okta Admin Console'\n    selection_positive:\n        - debugContext.debugData.behaviors|contains: 'POSITIVE'\n        - debugContext.debugData.logOnlySecurityData|contains: 'POSITIVE'\n    condition: all of selection_*\nfalsepositives:\n    - When an admin begins using the Admin Console and one of Okta's heuristics incorrectly identifies the behavior as being unusual.\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1078.004","id":"T1078.004","name":"Cloud Accounts","page":"techniques/enterprise/T1078.004/"}],"data_path":"data/detection-rules/a0b38b70-3cb5-484b-a4eb-c4d8e7bcc0a9.json","kind":"sigma"}
