Elastic low stable kql

Attempt to Delete an Okta Policy Rule

Detects attempts to delete a rule within an Okta policy. An adversary may attempt to delete an Okta policy rule in order to weaken an organization's security controls.

View Source

Detection Logic

data_stream.dataset:okta.system and event.action:policy.rule.delete

False Positives

  • Consider adding exceptions to this rule to filter false positives if Okta MFA rules are regularly modified in your organization.

Field Validations

Loading…

Comments (0)

Loading comments...