Elastic low stable kql

Attempt to Revoke Okta API Token

Identifies attempts to revoke an Okta API token. An adversary may attempt to revoke or delete an Okta API token to disrupt an organization's business operations.

View Source

Detection Logic

data_stream.dataset:okta.system and event.action:system.api_token.revoke

False Positives

  • If the behavior of revoking Okta API tokens is expected, consider adding exceptions to this rule to filter false positives.

Field Validations

Loading…

Comments (0)

Loading comments...