Okta admin function access via proxy (requestUri contains admin and isProxy enabled)

Flags Okta requests targeting admin URIs when the event indicates the traffic is proxied.

FreeReviewedSigma · Medium · v4
Product
okta
Service
okta
Author
Muhammad Faisal @faisalusuf (SigmaHQ), DRL 1.1
Published
2023-10-25
Updated
2026-07-31

What it detects

This rule flags Okta activity where the request URI contains the string "admin" while the request is marked as coming through a proxy. Such access can be used by attackers to reach privileged administrative endpoints while routing traffic through intermediary infrastructure. It relies on Okta telemetry fields for the requested URI and a proxy indicator to identify these events.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.