AWS Console Sign-In WITHOUT Okta Redirect
Description
A user has logged into the AWS console without authenticating via Okta. This rule requires AWS SSO via Okta and both log sources configured.
Query
Detection:
- Group:
- ID: Okta SSO to AWS
RuleID: Okta.SSO.to.AWS
Absence: true
- ID: AWS Console Sign-In
RuleID: AWS.Console.Sign-In
MatchCriteria:
field_name:
- GroupID: Okta SSO to AWS
Match: p_alert_context.actor
- GroupID: AWS Console Sign-In
Match: userIdentity.userName
Schedule:
RateMinutes: 1440
TimeoutMinutes: 5
LookbackWindowMinutes: 1800
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Panther group
AWS.Console.Sign-Inwithin 1800m
Excludes
Okta.SSO.to.AWS— excluded, not a dependency