Elastic high stable kql
Okta User Session Impersonation
A user has initiated a session impersonation granting them access to the environment with the permissions of the user they are impersonating. This would likely indicate Okta administrative access and should only ever occur if requested and expected.
Detection Logic
data_stream.dataset:okta.system and event.action:user.session.impersonation.initiate Field Validations
Loading…
Comments (0)
Loading comments...