Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
25 rules
Suspicious Okta Sign-On Policy Lifecycle Modification
This rule detects Okta policy lifecycle update or delete events affecting authentication policies. Adversaries who compromise an Okta admin weaken or remove sign-on and MFA policies to keep access, so lifecycle changes to policies warrant review against expected administration.
HuntRule TeamOktaoktaMedium61Premium2026-05-27Cisco Duo MFA Success Triggered by Admin-Assigned Bypass Code
Alert on Duo successful MFA logins that are attributed to bypass-user codes.
Nikita Khalimonenkov, Huntrule TeamCiscoduoMedium246Free2024-04-17Okta New User Created via user.lifecycle.create Event
Flags Okta events indicating new user account creation via user.lifecycle.create.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamOktaoktaInformational80Free2023-10-25Okta admin function access via proxy (requestUri contains admin and isProxy enabled)
Flags Okta requests targeting admin URIs when the event indicates the traffic is proxied.
Muhammad Faisal @faisalusuf, Huntrule TeamOktaoktaMedium415Free2023-10-25Okta user.session.start via anonymising proxy service
Identifies Okta user session starts where the session is marked as using an anonymizing proxy.
kelnage, Huntrule TeamOktaoktaHigh364Free2023-09-07Okta: End-user Reported Suspicious Activity Account Event Detection
Flags Okta end-user self-submitted reports of potentially suspicious activity on their account.
kelnage, Huntrule TeamOktaoktaHigh308Free2023-09-07Okta Admin Console: New admin console activity via policy.evaluate_sign_on heuristics
Alerts when Okta policy evaluation shows POSITIVE debug heuristics for activity targeting the Okta Admin Console.
kelnage, Huntrule TeamOktaoktaHigh91Free2023-09-07Okta System Log: New Identity Provider Created via system.idp.lifecycle.create
Alerts on Okta events indicating a new identity provider was created.
kelnage, Huntrule TeamOktaoktaMedium103Free2023-09-07Okta FastPass blocks phishing authentication attempts via MFA
Alerts on Okta FastPass MFA failures where the declined reason indicates a known phishing attempt.
Austin Songer @austinsonger, Huntrule TeamOktaoktaHigh234Free2023-05-07Okta Failed Login with Password-Like AlternateID Value
Alerts on Okta login_failed events with alternateId values that may contain password data, risking credential exposure in logs.
kelnage, Huntrule TeamOktaoktaHigh133Free2023-04-03Okta Admin Role Assignment Created via iam.resourceset.bindings.add
Detects creation of new admin role assignments in Okta when an IAM resource set binding is added.
Nikita Khalimonenkov, Huntrule TeamOktaoktaMedium371Free2023-01-19OneLogin: Detect API user account lock or suspension events
Flags OneLogin API events indicating a user account was locked or suspended.
Austin Songer @austinsonger, Huntrule TeamOneloginonelogin.eventsLow133Free2021-10-12OneLogin: User Assumes Another Account via Event Type 3
Alerts on OneLogin events indicating a user assumed another user account via event_type_id 3.
Austin Songer @austinsonger, Huntrule TeamOneloginonelogin.eventsLow161Free2021-10-12Okta MFA Deactivation or Full Factor Reset Event Detection
Flags Okta events indicating MFA deactivation or reset_all actions by a user or actor.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium387Free2021-09-21Okta User Account Lockout Triggered by Max Sign-In Attempts
Flags Okta user account lockouts triggered by exceeding the max sign-in attempts threshold.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium152Free2021-09-12