This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Okta Password in AlternateID Field
Original Source:
[Sigma source]
Title:
Potential Okta Password in AlternateID Field
Status:
test
Description:
Detects when a user has potentially entered their password into the username field, which will cause the password to be retained in log files.
References:
-https://developer.okta.com/docs/reference/api/system-log/
-https://www.mitiga.io/blog/how-okta-passwords-can-be-compromised-uncovering-a-risk-to-user-data
-https://help.okta.com/en-us/Content/Topics/users-groups-profiles/usgp-create-character-restriction.htm
Author:
kelnage
Date:
2023-04-03
modified:
2026-04-27
Tags:
-'attack.credential-access'
-'attack.t1552'
Logsource:
product: okta
service: okta
Detection:
selection:
legacyEventType
:
'core.user_auth.login_failed'
filter_main:
actor.alternateId|re
:
'(^0oa.*|[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,10})'
condition
:
selection and not filter_main
Falsepositives:
-Unlikely
Level:
high