Elastic low stable kql
Attempt to Revoke Okta API Token
Identifies attempts to revoke an Okta API token. An adversary may attempt to revoke or delete an Okta API token to disrupt an organization's business operations.
Detection Logic
data_stream.dataset:okta.system and event.action:system.api_token.revoke False Positives
- ⚠ If the behavior of revoking Okta API tokens is expected, consider adding exceptions to this rule to filter false positives.
Field Validations
Loading…
Comments (0)
Loading comments...