elastic
medium
kql
Okta ThreatInsight Threat Suspected Promotion
Okta ThreatInsight is a feature that provides valuable debug data regarding authentication and authorization processes,
which is logged in the system. Within this data, there is a specific field called threat_suspected, which represents
Okta's internal evaluation of the authentication or authorization workflow. When this field is set to True, it suggests
the presence of potential credential access techniques, such as password-spraying, brute-forcing, replay attacks, and
other similar threats.