elastic
medium
kql
Multiple Device Token Hashes for Single Okta Session
This rule detects when a specific Okta actor has multiple device token hashes and multiple source IPs for a single Okta
session. This may indicate an authenticated session has been hijacked or replayed from a different device and network.
Adversaries may steal session cookies or tokens to gain unauthorized access to Okta admin console, applications,
tenants, or other resources.