Detectionmediumtest
Okta API Token Revoked
Detects when a API Token is revoked.
Convert In Phoenix Studio
Open this Sigma rule in the converter with the YAML preloaded and ready for backend selection.
Launch
Log Source
Oktaokta
ProductOkta← raw: okta
Serviceokta← raw: okta
Detection Logic
Detection Logic1 selector
detection:
selection:
eventtype: system.api_token.revoke
condition: selectionFalse Positives
Unknown
False positive likelihood has not been assessed. Additional context may be needed during triage.
MITRE ATT&CK
Tactics
Rule Metadata
Rule ID
cf1dbc6b-6205-41b4-9b88-a83980d2255b
Status
test
Level
medium
Type
Detection
Created
Sun Sep 12
Modified
Sun Oct 09
Author
Path
rules/identity/okta/okta_api_token_revoked.yml
Raw Tags
attack.impact