Detectionhightest
Okta FastPass Phishing Detection
Detects when Okta FastPass prevents a known phishing site.
Convert In Phoenix Studio
Open this Sigma rule in the converter with the YAML preloaded and ready for backend selection.
Launch
Log Source
Oktaokta
ProductOkta← raw: okta
Serviceokta← raw: okta
Detection Logic
Detection Logic1 selector
detection:
selection:
outcome.reason: 'FastPass declined phishing attempt'
outcome.result: FAILURE
eventtype: user.authentication.auth_via_mfa
condition: selectionFalse Positives
Unlikely
False positives are unlikely for most environments. High confidence detection.
MITRE ATT&CK
Tactics
Techniques
Rule Metadata
Rule ID
ee39a9f7-5a79-4b0a-9815-d36b3cf28d3e
Status
test
Level
high
Type
Detection
Created
Sun May 07
Author
Path
rules/identity/okta/okta_fastpass_phishing_detection.yml
Raw Tags
attack.initial-accessattack.t1566