Okta: Detect API token revocation events

Flags Okta API token revocations using system.api_token.revoke System Log events.

FreeReviewedSigma · Medium · v4
Product
okta
Service
okta
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-09-12
Updated
2026-07-31

What it detects

This rule identifies when an Okta API token is revoked, based on the system event type system.api_token.revoke. Token revocation is security-relevant because it can indicate response to compromise, administrative changes, or attacker attempts to disrupt access. The detection relies on Okta system log telemetry containing the eventType field for API token revocations.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.