Suspicious SSO authentication
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Okta
Detection Modules
Identity Analytics
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Valid Accounts (T1078)
Severity
Informational
Description
A suspicious SSO authentication was made by a user.
Attacker's Goals
Achieve initial access to a company's resources.
Investigative actions
See whether this was a legitimate action.
Review the external IP/domain involved in the alert.
Contact the user whose account is being accessed and verify that they are actually attempting to log in.
Check if the login attempt is coming from an unfamiliar location or device.
Look for unusual login patterns, such as login attempts at odd hours.
Monitor the user's account for further unusual activity.
Variations
Was this helpful?
