elastic / elastic/detection-rules

[New Rule] Multiple Okta MFA push requests were denied

Open
#2,304 5 comments 1 reaction 0 assignees View on GitHub
backlog Rule: New
Dominant language
Python
Stars
2.7k
Forks
696
Avg merge
4d 17h
Merged PRs (30d)
87

Description

## Description
This rule is intended to alert when there are 2 or more `deny_push` events in Okta. The purpose is to detect when an attacker is attempting to spam MFA push requests to a user until they accept.

## Required Info

### Target indexes

filebeat-*

### Additional requirements

`event.module: okta`

### Platforms

Okta

## Optional Info
This is a threshold detection rule. A similar rule could be written with EQL.

### Query
![Screenshot 2022-09-19 at 13 56 05](https://user-images.githubusercontent.com/14032876/191011808-ced16cfe-fd57-4e7b-87e8-106c13193831.png)

### New fields required in ECS/data sources for this rule?

### Related issues or PRs

### References

## Example Data

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.