Elastic high stable kql

Okta User Session Impersonation

A user has initiated a session impersonation granting them access to the environment with the permissions of the user they are impersonating. This would likely indicate Okta administrative access and should only ever occur if requested and expected.

View Source

Detection Logic

data_stream.dataset:okta.system and event.action:user.session.impersonation.initiate

Field Validations

Loading…

Comments (0)

Loading comments...