Detectionmediumtest
Okta MFA Reset or Deactivated
Detects when an attempt at deactivating or resetting MFA.
Convert In Phoenix Studio
Open this Sigma rule in the converter with the YAML preloaded and ready for backend selection.
Launch
Log Source
Oktaokta
ProductOkta← raw: okta
Serviceokta← raw: okta
Detection Logic
Detection Logic1 selector
detection:
selection:
eventtype:
- user.mfa.factor.deactivate
- user.mfa.factor.reset_all
condition: selectionFalse Positives
If a MFA reset or deactivated was performed by a system administrator.
MITRE ATT&CK
Rule Metadata
Rule ID
50e068d7-1e6b-4054-87e5-0a592c40c7e0
Status
test
Level
medium
Type
Detection
Created
Tue Sep 21
Modified
Sun Oct 09
Author
Path
rules/identity/okta/okta_mfa_reset_or_deactivated.yml
Raw Tags
attack.persistenceattack.credential-accessattack.defense-evasionattack.t1556.006