Elastic low stable kql
Attempt to Delete an Okta Policy Rule
Detects attempts to delete a rule within an Okta policy. An adversary may attempt to delete an Okta policy rule in order to weaken an organization's security controls.
Detection Logic
data_stream.dataset:okta.system and event.action:policy.rule.delete False Positives
- ⚠ Consider adding exceptions to this rule to filter false positives if Okta MFA rules are regularly modified in your organization.
Field Validations
Loading…
Comments (0)
Loading comments...