Multiple Okta Users With Invalid Credentails From The Same IP

Description

This search detects Okta login failures due to bad credentials for multiple users originating from the same ip address.

Content Mapping

This content is not mapped to any local saved search. Add mapping


Use Case

Security Monitoring

Category

Adversary Tactics

Alert Volume

This search detects Okta login failures due to bad credentials for multiple users originating from the same ip address.

SPL Difficulty

None

Journey

Stage 2

MITRE ATT&CK Tactics

Defense Evasion
Persistence
Privilege Escalation
Initial Access

MITRE ATT&CK Techniques

Valid Accounts

Default Accounts

Data Sources

Okta

   Help

Multiple Okta Users With Invalid Credentails From The Same IP Help

This search is specific to Okta and requires Okta logs are being ingested in your Splunk deployment.

   Search

Open in Search