Okta Admin Console: New admin console activity via policy.evaluate_sign_on heuristics

Alerts when Okta policy evaluation shows POSITIVE debug heuristics for activity targeting the Okta Admin Console.

FreeReviewedSigma · High · v4
Product
okta
Service
okta
Author
kelnage (SigmaHQ), DRL 1.1
Published
2023-09-07
Updated
2026-07-31

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags Okta events where a policy decision for sign-on is evaluated against the target “Okta Admin Console” and the event’s debug heuristics indicate a “POSITIVE” behavior. Attackers may use the Admin Console for privilege escalation or persistence, and these signals can help surface newly identified or atypical admin-console-related activity. Telemetry relies on Okta system log fields including eventType, target.displayName, and debugContext.debugData values containing the marker strings.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious Google Cloud Function Create or Update Triggering Build
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
Suspicious AWS Console Login Without MFA
Suspicious Cloud Sign-In From an Anonymizer or High-Risk Session (via signinlogs)
Okta Admin Console: New admin console activity via policy.evaluate_sign_on heuristics
Pivot detection · T1078.004 · 9 related

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.