Panther critical experimental python
Potential Compromised Okta Credentials
Identifies high-confidence credential compromise by detecting Okta login without Push Security verification followed by Push Security phishing attack within 60 minutes. This sequence indicates an attacker authenticated to Okta with stolen credentials then attempted MFA fatigue or push bombing attacks. The correlation of both events provides strong evidence of active account compromise requiring immediate response.
Detection Logic
[object Object] Field Validations
Loading…
Comments (0)
Loading comments...