Okta 2023 Breach Indicator Of Compromise


Description

Detects new user account creation or activation with specific names related to the Okta Support System 2023 breach. This rule can be enhanced by filtering out known and legitimate username used in your environnement.

Query · sigma

selection:
  eventType:
  - user.lifecycle.create
  - user.lifecycle.activate
  target.displayName|contains: svc_network_backup
condition: selection

Known false positives

  • Unknown
Raw source Okta 2023 Breach Indicator Of Compromise · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: Okta 2023 Breach Indicator Of Compromise
id: 00a8e92a-776b-425f-80f2-82d8f8fab2e5
status: test
description: |
    Detects new user account creation or activation with specific names related to the Okta Support System 2023 breach.
    This rule can be enhanced by filtering out known and legitimate username used in your environnement.
author: Muhammad Faisal (@faisalusuf)
date: 2023-10-25
modified: 2026-04-27
references:
    - https://www.beyondtrust.com/blog/entry/okta-support-unit-breach
    - https://developer.okta.com/docs/reference/api/event-types/
tags:
    - attack.credential-access
    - detection.emerging-threats
logsource:
    service: okta
    product: okta
detection:
    selection:
        eventType:
            - 'user.lifecycle.create'
            - 'user.lifecycle.activate'
        target.displayName|contains: 'svc_network_backup'
    condition: selection
falsepositives:
    - Unknown
level: medium

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.