Okta phishing detection with FastPass origin check

Set up the okta integration.

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect when Okta raises a phishing detection with FastPass origin check.

Strategy

This rule monitors Okta for when a phishing detection with FastPass origin check has been raised. Okta provides a platform detection for when a user enrolled in FastPass fails to authenticate via a real-time adversary in the middle (AiTM) phishing proxy.

Triage and response

  1. Extract the attackers IP address {{@network.client.ip}}.
  2. Determine if any other users have authenticated from this address.
  3. If yes, clear any user sessions and reset passwords if the users entered a password as part of the authenitication flow.
  4. Begin your organization’s incident response process and investigate for any account takeovers.
PREVIEWING: may/unit-testing