Possible AiTM Phishing Sign-On Evaluation Denied by Okta FastPass

PremiumReviewedSigma · Medium · v1
Product
okta
Service
okta
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects Okta sign-on policy evaluations that are challenged or denied where the network reputation flags a phishing or proxy origin, matching FastPass anti-phishing rejections. In this campaign an adversary-in-the-middle proxy relayed authentication and Okta FastPass declined the phishing attempt during policy evaluation. Clusters of such denials indicate active AiTM targeting of user credentials and session tokens.

Related detections9 linkedT1566.002 — drag to rearrange
Suspicious Cloudflare Workers Brand-Impersonation Phishing Domains via Proxy
Suspicious NFe-Themed Brazilian Lure Executable Execution
Malicious Evilginx AiTM Phishing Proxy Default TLS Certificate
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Malicious TCP Session Hijacking via rshijack
Suspicious Phishing URL with Unrendered Template Placeholder (via proxy)
Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
Suspicious Spoofed Inbound Email With Failed Authentication and Anonymous Internal Sender (via m365)
Malicious Credential Harvesting Request via All-in-1 PHP Endpoint (via proxy)
Possible AiTM Phishing Sign-On Evaluation Denied by Okta FastPass
Pivot detection · T1566.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.