Detectionmediumtest

Okta MFA Reset or Deactivated

Detects when an attempt at deactivating or resetting MFA.

Convert In Phoenix Studio

Open this Sigma rule in the converter with the YAML preloaded and ready for backend selection.

Launch
Austin SongerCreated Tue Sep 21Updated Sun Oct 0950e068d7-1e6b-4054-87e5-0a592c40c7e0identity
Log Source
Oktaokta
ProductOkta← raw: okta
Serviceokta← raw: okta
Detection Logic
Detection Logic1 selector
detection:
    selection:
        eventtype:
            - user.mfa.factor.deactivate
            - user.mfa.factor.reset_all
    condition: selection
False Positives

If a MFA reset or deactivated was performed by a system administrator.

Rule Metadata
Rule ID
50e068d7-1e6b-4054-87e5-0a592c40c7e0
Status
test
Level
medium
Type
Detection
Created
Tue Sep 21
Modified
Sun Oct 09
Path
rules/identity/okta/okta_mfa_reset_or_deactivated.yml
Raw Tags
attack.persistenceattack.credential-accessattack.defense-evasionattack.t1556.006
View on GitHub