Okta Security
| eventType | Description | Sample | Rule |
|---|---|---|---|
| security. | Fired when Threat Insight detects that an org is no longer under attack. | N | Y |
| security. | Fired when Threat Insight detects that an org is under attack. | N | Y |
| security. | Triggered when settings to protect against password-based attacks are updated. | N | N |
| security. | Fired when an admin activates an authenticator for the org. | Y | N |
| security. | Fired when an admin creates an authenticator for the org. | N | N |
| security. | Fired when an admin deactivates an authenticator for the org. | N | N |
| security. | Fired when an admin updates an authenticator in the org. | Y | N |
| security. | Behavior settings create. | N | N |
| security. | Behavior settings delete. | N | N |
| security. | Behavior settings update. | N | N |
| security. | A credential, such as a password, which is associated with a known breach was used during an authentication flow. | N | N |
| security. | Added request blacklist to request blacklist policies. | N | N |
| security. | Removed request blacklist from request blacklist policies. | N | N |
| security. | Temporarily disabling blacklisting. | N | N |
| security. | Activate a security events provider. | N | N |
| security. | Create a security events provider. | N | N |
| security. | Deactivate a security events provider. | N | N |
| security. | Delete a security events provider. | N | N |
| security. | Appears when a security events provider submits a valid event for each known detection. | N | N |
| security. | Update a security events provider. | N | N |
| security. | Create security events transmitter. | N | N |
| security. | Delete security events transmitter. | N | N |
| security. | Update security events transmitter. | N | N |
| security. | Protected action attempted. | Y | N |
| security. | Protected action setting disabled. | N | N |
| security. | Security request blocked. | Y | N |
| security. | Roaming session detected for user. | N | N |
| security. | Session Protection status was updated to monitoring or enforced. | N | N |
| security. | Fired when a ThreatInsight configuration has been updated. | N | N |
| security. | Request from an IP identified as malicious by Okta ThreatInsight. | Y | Y |
| security. | A trusted origin is activated. | Y | N |
| security. | A trusted origin is created. | Y | N |
| security. | A trusted origin is deactivated. | Y | N |
| security. | A trusted origin is deleted. | Y | N |
| security. | A trusted origin is updated. | Y | N |
| security. | Fired when a country has been added to the voice call blacklist. | N | N |
| security. | Fired when a country has been removed from the voice call blacklist. | N | N |
| security. | Added IPs to blacklist zone. | N | N |
| security. | Removed IPs from blacklist zone. | N | N |
security.attack.end
#Description
Fired when Threat Insight detects that an org is no longer under attack. This can be used to monitor when our models no longer detect an attack on an org. When this event is fired, Threat Insight will stop being extra aggressive in logging and/or blocking suspicious requests. This is fired from within an internal Okta context and therefore will not have any request level context information.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
okta::client.ipAddress (kusto rule field) | is_not_null | | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1098, T1098.005↳ also matches security.attack.start, security.threat.detected
References #
security.attack.start
#Description
Fired when Threat Insight detects that an org is under attack. This can be used to monitor attacks against your organization. When this event is fired, Threat Insight will automatically become more aggressive in logging and/or blocking suspicious requests. This is fired from within an internal Okta context and therefore will not have any request level context information.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
okta::client.ipAddress (kusto rule field) | is_not_null | | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1098, T1098.005↳ also matches security.attack.end, security.threat.detected YARA-L #
T1110
References #
security.attack_protection.settings.update
#Description
Triggered when settings to protect against password-based attacks are updated. Useful for monitoring potential intrusion if the change was not planned. Covered features include Require possession factor before password during MFA and Block suspicious password attempts from unknown devices.
References #
security.authenticator.lifecycle.activate
#Description
Fired when an admin activates an authenticator for the org. This event can be used to identify who activated an authenticator and which authenticator was activated. When fired, this event contains information about the authenticator type that was activated and the actor who activated the authenticator. Authenticator activation occurs when an authenticator is added. Related events include security.authenticator.lifecycle.deactivate.
Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.Example System Log Event #
{
"published": 1784656596948,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000079",
"actor": {
"id": "00u00000000000000026",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000027"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0",
"os": "Windows 10",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "aut00000000000000280",
"type": "Authenticator",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 93",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.22",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "security.authenticator.lifecycle.activate",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000040",
"detail": {}
},
"debugContext": {
"debugData": {
"authenticatorKey": "webauthn",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000040",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000002",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "00000000000000000000000000000000000000000000000000000000000003",
"url": "00000000000000000000000000000000000000000000000000000000000003?"
}
},
"displayMessage": "Authenticator activated",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Device",
"id": "bhv00000000000000031",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000032",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000033",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000034",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000035",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000036",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000037",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000038",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000281",
"externalSessionId": "10200000000000000281"
}
}
References #
security.authenticator.lifecycle.create
#Description
Fired when an admin creates an authenticator for the org. This event can be used to identify who created an authenticator and which authenticator was created. The actor specifies the user that created the authenticator and the target specifies the authenticator name and the id. This event could also contain some authenticator specific information. Authenticator creation occurs when an authenticator is added. Related events include security.authenticator.lifecycle.update.
Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.References #
security.authenticator.lifecycle.deactivate
#Description
Fired when an admin deactivates an authenticator for the org. This event can be used to identify who deactivated an authenticator and which authenticator was deactivated. When fired, this event contains information about the authenticator type that was deactivated and the actor who deactivated the authenticator. Authenticator deactivation occurs when an authenticator is removed. Related events include security.authenticator.lifecycle.activate.
Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.References #
security.authenticator.lifecycle.update
#Description
Fired when an admin updates an authenticator in the org. This event can be used to identify who updated an authenticator and which authenticator was updated. The actor specifies the user that updated the authenticator and the target specifies the authenticator name and the ID. There may be a second target with details of any authenticator method updates. This event could also contain authenticator specific information. Authenticator update occurs when an authenticator is edited. Related events include security.authenticator.lifecycle.create.
Only generated on Okta Identity Engine (OIE) orgs, not Classic Engine (Okta Classic) orgs.Example System Log Event #
{
"published": 1780401778564,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000080",
"actor": {
"id": "00u00000000000000153",
"type": "User",
"alternateId": "user08@dw-harness.example",
"displayName": "DW Harness 10",
"detailEntry": {
"realmId": "guo00000000000000062"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:151.0) Gecko/20100101 Firefox/151.0",
"os": "Windows 10",
"browser": "FIREFOX"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.5",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "aut00000000000000282",
"type": "Authenticator",
"alternateId": "user06@dw-harness.example",
"displayName": "DW Harness 94",
"detailEntry": null
}
],
"outcome": {
"result": "SUCCESS",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.5",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "security.authenticator.lifecycle.update",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000041",
"detail": {}
},
"debugContext": {
"debugData": {
"authenticatorKey": "okta_verify",
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000041",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000019",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "0000000000000000000000000000000000000000013",
"url": "0000000000000000000000000000000000000000013?"
}
},
"displayMessage": "Authenticator updated",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New ASN",
"id": "bhv00000000000000155",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000156",
"result": "NEGATIVE"
},
{
"name": "New State",
"id": "bhv00000000000000157",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000158",
"result": "BAD_REQUEST"
},
{
"name": "New Geo-Location",
"id": "bhv00000000000000159",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000160",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000161",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000162",
"result": "BAD_REQUEST"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000283",
"externalSessionId": "10200000000000000283"
}
}
References #
security.behavior.settings.create
#Description
Behavior settings create. This can also be used to identify when a behavior setting is created. When fired, this event contains information about a created setting.
References #
security.behavior.settings.delete
#Description
Behavior settings delete. This can also be used to identify when a behavior setting has been deleted. When fired, this event contains information about a delete setting.
References #
security.behavior.settings.update
#Description
Behavior settings update. This can also be used to identify when a behavior setting has been changed. When fired, this event contains information about a updated setting.
References #
security.breached_credential.detected
#Description
A credential, such as a password, which is associated with a known breach was used during an authentication flow. Used to identify users for whom credential rotation or other risk mitigation is necessary. The actor is the user with the breached credential. For Identity Engine, a target will indicate the specific credential associated with the breach. The outcome for this event will always be SUCCESS with a severity level of WARN. If breached credential protection is enabled, auser.session.clear will also be fired. These two events can be correlated by the Request ID.
References #
security.device.add_request_blacklist_policy
#Description
Added request blacklist to request blacklist policies.
References #
security.device.remove_request_blacklist_policy
#Description
Removed request blacklist from request blacklist policies.
References #
security.device.temporarily_disable_blacklisting
#Description
Temporarily disabling blacklisting.
References #
security.events.provider.activate
#Description
Activate a security events provider. Appears when an authorized security events provider, such as the Shared Signals Framework (SSF) transmitter, is activated.This event helps admins troubleshoot issues with the delivery of security events to Okta. When fired, this event contains information about the activated security events provider.
References #
security.events.provider.create
#Description
Create a security events provider. Appears when an authorized security events provider, such as the Shared Signals Framework (SSF) transmitter, is created.This event helps admins troubleshoot issues with the delivery of security events to Okta. When fired, this event contains information about the created security events provider.
References #
security.events.provider.deactivate
#Description
Deactivate a security events provider. Appears when an authorized security events provider, such as the Shared Signals Framework (SSF) transmitter, is deactivated.This event helps admins troubleshoot issues with the delivery of security events to Okta. When fired, this event contains information about the deactivated security events provider.
References #
security.events.provider.delete
#Description
Delete a security events provider. Appears when an authorized security events provider, such as the Shared Signals Framework (SSF) transmitter, is deleted.This event helps admins troubleshoot issues with the delivery of security events to Okta. When fired, this event contains information about the deleted security events provider.
References #
security.events.provider.receive_event
#Description
Appears when a security events provider submits a valid event for each known detection. The event helps admins debug or monitor SSF provider submissions. The event contains debug context data about the provider's risk report.
References #
security.events.provider.update
#Description
Update a security events provider. Appears when an update is made to an authorized security events provider,such as the Shared Signals Framework (SSF) transmitter.This event helps admins troubleshoot issues with the delivery of security events to Okta. When fired, this event contains information about the updated security events provider.
References #
security.events.transmitter.create
#Description
Create security events transmitter. Appears when a specific security events transmitter, such as the Shared Signals Framework (SSF) transmitter, is created. This event helps admins troubleshoot issues with event delivery to security event receivers. This event contains configuration details of the created security events transmitter.
References #
security.events.transmitter.delete
#Description
Delete security events transmitter. Appears when a specific security events transmitter, such as the Shared Signals Framework (SSF) transmitter, is deleted. This event helps admins troubleshoot issues with event delivery to security events receivers. This event contains configuration details of the deleted security events transmitter.
References #
security.events.transmitter.update
#Description
Update security events transmitter. Appears when there is an update to a specific security events transmitter, such as the Shared Signals Framework (SSF) transmitter. This event helps admins troubleshoot issues with event delivery to security events receivers. This event contains configuration details of the updated security events transmitter.
References #
security.protected_action.attempt
#Description
Protected action attempted. This event can be used to track and audit when a protected action is attempted. When fired this event contains information about what protected action is attempted.
Example System Log Event #
{
"published": 1785258176522,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000081",
"actor": {
"id": "00u00000000000000093",
"type": "User",
"alternateId": "user20@dw-harness.example",
"displayName": "DW Harness 30",
"detailEntry": {
"realmId": "guo00000000000000044"
}
},
"client": {
"userAgent": {
"rawUserAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"os": "Mac OS X",
"browser": "CHROME"
},
"zone": "null",
"device": "Computer",
"id": null,
"ipAddress": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"events": null,
"target": [
{
"id": "0000000000000000000002",
"type": "Protected Action",
"alternateId": null,
"displayName": "DW Harness 95",
"detailEntry": null
}
],
"outcome": {
"result": "CHALLENGE",
"reason": null
},
"request": {
"ipChain": [
{
"ip": "192.0.2.4",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"version": "0",
"severity": "INFO",
"eventType": "security.protected_action.attempt",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000042",
"detail": {}
},
"debugContext": {
"debugData": {
"behaviors": "{New Geo-Location=BAD_REQUEST, New Device=BAD_REQUEST, New ASN=BAD_REQUEST, New IP=NEGATIVE, New State=BAD_REQUEST, New Country=BAD_REQUEST, Velocity=BAD_REQUEST, New City=BAD_REQUEST}",
"requestId": "00000000000000000000000000000042",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000012",
"origin": "https://app.example.com",
"risk": "{reasons=Anomalous Location, level=MEDIUM}",
"requestUri": "000000000000000000000000000000000000000000000000000000000000002",
"url": "000000000000000000000000000000000000000000000000000000000000002?"
}
},
"displayMessage": "Protected action attempted",
"gatewayContext": null,
"legacyEventType": null,
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
},
"risk": {
"level": "MEDIUM",
"reasons": [
"Anomalous Location"
]
},
"userBehaviors": [
{
"name": "New Geo-Location",
"id": "bhv00000000000000052",
"result": "BAD_REQUEST"
},
{
"name": "New ASN",
"id": "bhv00000000000000053",
"result": "BAD_REQUEST"
},
{
"name": "New City",
"id": "bhv00000000000000054",
"result": "BAD_REQUEST"
},
{
"name": "New Country",
"id": "bhv00000000000000055",
"result": "BAD_REQUEST"
},
{
"name": "New Device",
"id": "bhv00000000000000056",
"result": "BAD_REQUEST"
},
{
"name": "New State",
"id": "bhv00000000000000057",
"result": "BAD_REQUEST"
},
{
"name": "Velocity",
"id": "bhv00000000000000058",
"result": "BAD_REQUEST"
},
{
"name": "New IP",
"id": "bhv00000000000000059",
"result": "NEGATIVE"
}
]
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "10200000000000000142",
"externalSessionId": "10200000000000000142"
}
}
References #
security.protected_action.settings.update
#Description
Protected action setting disabled. This event can be used to track and audit when a protected action setting is updated. When fired this event contains information about what protected action setting is updated.
References #
security.request.blocked
#Description
Security request blocked.
Example System Log Event #
{
"published": 1784429967280,
"id": null,
"etag": null,
"kind": null,
"uuid": "00000000-0000-0000-0000-000000000082",
"actor": {
"id": "spr00000000000000171",
"type": "SystemPrincipal",
"alternateId": "user41@dw-harness.example",
"displayName": "Okta System",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "app.example.com.android.auth/9.1.0 Android/16 samsung/SM-A566E XFTdLJQkTJmamujxdFhubw",
"os": "Android",
"browser": "UNKNOWN"
},
"zone": "DefaultEnhancedDynamicZone",
"device": "Mobile",
"id": null,
"ipAddress": "192.0.2.28",
"geographicalContext": null
},
"device": null,
"events": null,
"target": [
{
"id": "nzo00000000000000284",
"type": "Blocklist",
"alternateId": null,
"displayName": "DW Harness 96",
"detailEntry": {
"zoneNameMatch": "DefaultEnhancedDynamicZone"
}
}
],
"outcome": {
"result": "SUCCESS",
"reason": "NETWORK_ZONE_BLOCKLIST"
},
"request": {
"ipChain": [
{
"ip": "192.0.2.28",
"geographicalContext": null,
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"ipServiceCategories": [
{
"type": "VPN",
"isAnonymous": true
},
{
"operator": "NORD_VPN",
"type": "VPN",
"isAnonymous": true
}
]
}
}
]
},
"version": "0",
"severity": "WARN",
"eventType": "security.request.blocked",
"ipAddress": null,
"networkInfo": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000000000000043",
"detail": {}
},
"debugContext": {
"debugData": {
"tunnels": [
{
"anonymous": true,
"operator": "NORD_VPN",
"type": "VPN"
}
],
"requestId": "00000000000000000000000000000043",
"requestUri": "/.well-known/ov-configurations",
"url": "/.well-known/ov-configurations?"
}
},
"displayMessage": "Blocked request from IP: 192.0.2.29, IPServiceCategory: NORD_VPN",
"gatewayContext": null,
"legacyEventType": "security.zone.request.blocked",
"resourceDetails": null,
"securityContext": {
"asNumber": 0,
"asOrg": null,
"isp": null,
"domain": null,
"isProxy": true,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"ipServiceCategories": [
{
"type": "VPN",
"isAnonymous": true
},
{
"operator": "NORD_VPN",
"type": "VPN",
"isAnonymous": true
}
]
}
},
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000003",
"externalSessionId": "0000003"
}
}
References #
security.session_protection.status.update
#Description
Session Protection status was updated to monitoring or enforced. Indicates a change in the Session Protection status - (monitoring or enforced).
References #
security.threat.configuration.update
#Description
Fired when a ThreatInsight configuration has been updated. This can be used to identify when an existing ThreatInsight configuration has been updated. An update can be updating the action or the excluded zones. When fired, this event contains information about who made the update to the configuration.
References #
security.threat.detected
#Description
Request from an IP identified as malicious by Okta ThreatInsight. This can be used to monitor and act on credential based attacks (such as Brute Force, Password Spray) on your organization. The reasons why the request was classified as malicious can be found in the outcome.reason field. The outcome.result field will be 'ALLOW', 'DENY' or 'RATE_LIMIT' based on whether Okta Threat Insight is configured in log mode or log and enforce mode, where 'ALLOW' means the request continued, 'DENY' means the request was blocked and 'RATE_LIMIT' means we protected your org from exceeding your rate limit by not allowing suspicious activity to count towards your rate limit.
Example System Log Event #
{
"actor": {
"alternateId": "user07@dw-harness.example",
"detailEntry": null,
"displayName": "DW Harness 17",
"id": "000000000066",
"type": "IP address"
},
"authenticationContext": {
"authenticationProvider": null,
"authenticationStep": 0,
"credentialProvider": null,
"credentialType": null,
"externalSessionId": null,
"interface": null,
"issuer": null
},
"client": {
"device": "Mobile",
"geographicalContext": {
"city": "Anytown",
"country": "Placeholderland",
"geolocation": {
"lat": 0.0,
"lon": 0.0
},
"postalCode": "00000",
"state": "Anystate"
},
"id": null,
"ipAddress": "198.51.100.9",
"userAgent": {
"browser": "CHROME",
"os": "Android",
"rawUserAgent": "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Mobile Safari/537.36"
},
"zone": "null"
},
"debugContext": {
"debugData": {
"dtHash": "0000000000000000000000000000000000000000000000000000000000000067",
"requestId": "00000000000000000000000000000068",
"requestUri": "/api/internal/brand/theme/style-sheet",
"threatDetections": {
"Login Failures": "HIGH"
},
"threatSuspected": "true",
"url": "/api/internal/brand/theme/style-sheet?touch-point=ERROR_PAGE&v=000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000003"
}
},
"device": null,
"displayMessage": "Request from suspicious actor",
"eventType": "security.threat.detected",
"legacyEventType": "security.threat.detected",
"outcome": {
"reason": "Login Failures",
"result": "DENY"
},
"published": "2024-03-28T08:39:54.374Z",
"request": {
"ipChain": [
{
"geographicalContext": {
"city": "Anytown",
"country": "Placeholderland",
"geolocation": {
"lat": 0.0,
"lon": 0.0
},
"postalCode": "00000",
"state": "Anystate"
},
"ip": "198.51.100.9",
"source": null,
"version": "V4"
}
]
},
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"domain": "example.com",
"isProxy": false,
"isp": "example-isp"
},
"severity": "WARN",
"target": null,
"transaction": {
"detail": {},
"id": "00000000000000000000000000000068",
"type": "WEB"
},
"uuid": "00000000-0000-0000-0000-000000000009",
"version": "0"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
eventType | eq | security.threat.detected | 2 rules | sigma, splunk |
okta::client.ipAddress (kusto rule field) | is_not_null | | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
Elastic #
Splunk #
T1078, T1078.004Kusto #
T1098, T1098.005↳ also matches security.attack.end, security.attack.start YARA-L #
T1110T1110T1110Panther #
References #
security.trusted_origin.activate
#Description
A trusted origin is activated. When an event is emitted upon the activation of a trusted origin, customers can monitor these events and take remedial action. Event is triggered when a trusted origin is activated.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000069",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "A trusted origin is activated",
"eventType": "security.trusted_origin.activate",
"outcome": {
"result": "SUCCESS",
"reason": "trusted origin is activated"
},
"published": "2026-07-02T18:55:00.403Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/trustedOrigins/tos00000000000000009/lifecycle/activate",
"url": "/api/v1/trustedOrigins/tos00000000000000009/lifecycle/activate?"
}
},
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "TrustedOrigin",
"alternateId": null,
"displayName": "DW Harness",
"detailEntry": {
"trustedOriginStatus": "INACTIVE",
"trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com",
"trustedOriginScopes": [
{
"type": "CORS"
},
{
"type": "REDIRECT"
}
]
},
"changeDetails": {
"from": {
"trustedOriginStatus": "INACTIVE"
},
"to": {
"trustedOriginStatus": "ACTIVE"
}
}
}
]
}
References #
security.trusted_origin.create
#Description
A trusted origin is created. When an event is emitted upon the creation of a trusted origin, customers can monitor these events and take remedial action. Event is triggered when a trusted origin is created.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000070",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "A trusted origin is created",
"eventType": "security.trusted_origin.create",
"outcome": {
"result": "SUCCESS",
"reason": "trusted origin is created"
},
"published": "2026-07-02T18:55:00.241Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/trustedOrigins",
"url": "/api/v1/trustedOrigins?"
}
},
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "TrustedOrigin",
"alternateId": null,
"displayName": "DW Harness",
"detailEntry": {
"trustedOriginStatus": "ACTIVE",
"trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com",
"trustedOriginScopes": [
{
"type": "CORS"
},
{
"type": "REDIRECT"
}
]
}
}
]
}
References #
security.trusted_origin.deactivate
#Description
A trusted origin is deactivated. When an event is emitted upon the deactivation of a trusted origin, customers can monitor these events and take remedial action. Event is triggered when a trusted origin is deactivated.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000071",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "A trusted origin is deactivated",
"eventType": "security.trusted_origin.deactivate",
"outcome": {
"result": "SUCCESS",
"reason": "trusted origin is deactivated"
},
"published": "2026-07-02T18:55:00.554Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/trustedOrigins/tos00000000000000009/lifecycle/deactivate",
"url": "/api/v1/trustedOrigins/tos00000000000000009/lifecycle/deactivate?"
}
},
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "TrustedOrigin",
"alternateId": null,
"displayName": "DW Harness",
"detailEntry": {
"trustedOriginStatus": "ACTIVE",
"trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com",
"trustedOriginScopes": [
{
"type": "CORS"
},
{
"type": "REDIRECT"
}
]
},
"changeDetails": {
"from": {
"trustedOriginStatus": "ACTIVE"
},
"to": {
"trustedOriginStatus": "INACTIVE"
}
}
}
]
}
References #
security.trusted_origin.delete
#Description
A trusted origin is deleted. When an event is emitted upon the deletion of a trusted origin, customers can monitor these events and take remedial action. Event is triggered when a trusted origin is deleted.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000072",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "A trusted origin is deleted",
"eventType": "security.trusted_origin.delete",
"outcome": {
"result": "SUCCESS",
"reason": "trusted origin is deleted"
},
"published": "2026-07-02T18:55:00.638Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/trustedOrigins/tos00000000000000009",
"url": "/api/v1/trustedOrigins/tos00000000000000009?"
}
},
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "TrustedOrigin",
"alternateId": null,
"displayName": "DW Harness",
"detailEntry": {
"trustedOriginStatus": "INACTIVE",
"trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com",
"trustedOriginScopes": [
{
"type": "CORS"
},
{
"type": "REDIRECT"
}
]
},
"changeDetails": {
"from": {
"displayName": "DW Harness",
"trustedOriginScopes": [
{
"type": "CORS"
},
{
"type": "REDIRECT"
}
],
"trustedOriginStatus": "INACTIVE",
"trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com"
},
"to": null
}
}
]
}
References #
security.trusted_origin.update
#Description
A trusted origin is updated. When an event is emitted upon the modification of a trusted origin, customers can monitor these events and take remedial action. Event is triggered when a trusted origin is updated.
Example System Log Event #
{
"actor": {
"id": "00000000000000000000",
"type": "User",
"alternateId": "user@dw-harness.example",
"displayName": "DW Harness",
"detailEntry": null
},
"client": {
"userAgent": {
"rawUserAgent": "python-requests/2.34.2",
"os": "Unknown",
"browser": "UNKNOWN"
},
"zone": "null",
"device": "Unknown",
"id": null,
"ipAddress": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
}
},
"device": null,
"authenticationContext": {
"authenticationProvider": null,
"credentialProvider": null,
"credentialType": null,
"issuer": null,
"interface": null,
"authenticationStep": 0,
"rootSessionId": "0000000000000000000000073",
"externalSessionId": "00000000000000000000"
},
"displayMessage": "A trusted origin is updated",
"eventType": "security.trusted_origin.update",
"outcome": {
"result": "SUCCESS",
"reason": "trusted origin is updated"
},
"published": "2026-07-02T18:55:00.485Z",
"securityContext": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com",
"isProxy": false,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
},
"severity": "INFO",
"debugContext": {
"debugData": {
"requestId": "00000000000000000000",
"dtHash": "0000000000000000000000000000000000000000000000000000000000000000",
"requestUri": "/api/v1/trustedOrigins/tos00000000000000009",
"url": "/api/v1/trustedOrigins/tos00000000000000009?"
}
},
"legacyEventType": null,
"transaction": {
"type": "WEB",
"id": "00000000000000000000",
"detail": {
"rootApiTokenId": "00T00000000000000005",
"requestApiTokenId": "00T00000000000000005"
}
},
"uuid": "00000000-0000-0000-0000-000000000000",
"version": "0",
"request": {
"ipChain": [
{
"ip": "203.0.113.10",
"geographicalContext": {
"city": "Anytown",
"state": "Anystate",
"country": "Placeholderland",
"postalCode": "00000",
"geolocation": {
"lat": 0.0,
"lon": 0.0
}
},
"version": "V4",
"source": null,
"ipDetails": {
"asNumber": 0,
"asOrg": "example-as-org",
"isp": "example-isp",
"domain": "example.com"
}
}
]
},
"target": [
{
"id": "00000000000000000000",
"type": "TrustedOrigin",
"alternateId": null,
"displayName": "DW Harness",
"detailEntry": {
"trustedOriginStatus": "ACTIVE",
"trustedOriginUrl": "https://dw-harn-eeb5dfe9.example.com",
"trustedOriginScopes": [
{
"type": "CORS"
},
{
"type": "REDIRECT"
}
]
},
"changeDetails": {
"from": {
"displayName": "DW Harness"
},
"to": {
"displayName": "DW Harness"
}
}
}
]
}
References #
security.voice.add_country_blacklist
#Description
Fired when a country has been added to the voice call blacklist. This can be used to identify when a country has been blacklisted for voice call. When fired, this event contains information about the country that was added to the blacklist.Related events include security.voice.remove_country_blacklist.
References #
security.voice.remove_country_blacklist
#Description
Fired when a country has been removed from the voice call blacklist. This can be used to identify when a country has been removed from voice call blacklist. When fired, this event contains information about the country that was removed from the blacklist.Related events include security.voice.add_country_blacklist.