Potential Okta Password in AlternateID Field

 Original Source: [Sigma source]
Title: Potential Okta Password in AlternateID Field
Status: test
Description:Detects when a user has potentially entered their password into the username field, which will cause the password to be retained in log files.
References:
  -https://developer.okta.com/docs/reference/api/system-log/
  -https://www.mitiga.io/blog/how-okta-passwords-can-be-compromised-uncovering-a-risk-to-user-data
  -https://help.okta.com/en-us/Content/Topics/users-groups-profiles/usgp-create-character-restriction.htm
Author: kelnage
Date: 2023-04-03
modified:2026-04-27
Tags:
  • -'attack.credential-access'
  • -'attack.t1552'
Logsource:
  • product: okta
  • service: okta
Detection:
  selection:
    legacyEventType: 'core.user_auth.login_failed'
  filter_main:
    actor.alternateId|re: '(^0oa.*|[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,10})'
  condition:selection and not filter_main
Falsepositives:
  -Unlikely
Level: high