Okta: Detect security.threat.detected events in threat insight

Flags Okta System Log security.threat.detected events indicating a detected potential security threat.

FreeReviewedSigma · Medium · v4
Product
okta
Service
okta
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-09-12
Updated
2026-07-31

What it detects

This rule matches Okta System Log events with eventType equal to security.threat.detected. Such events indicate that Okta’s Threat Insight has flagged a potential security threat, which attackers may attempt to trigger or evade. Detection relies on the presence of the eventType field in Okta telemetry from the System Log.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.