Detection rules › Splunk

Okta Suspicious Use of a Session Cookie

Status
production
Severity
low
Group by
"debugContext.debugData.dtHash", user
Author
Scott Dermott, Felicity Robson, Okta, Michael Haag, Bhavin Patel, Splunk
Source
github.com/splunk/security_content

The following analytic identifies suspicious use of a session cookie by detecting multiple client values (IP, User Agent, etc.) changing for the same Device Token associated with a specific user. It leverages policy evaluation events from successful authentication logs in Okta. This activity is significant as it may indicate an adversary attempting to reuse a stolen web session cookie, potentially bypassing authentication mechanisms. If confirmed malicious, this could allow unauthorized access to user accounts, leading to data breaches or further exploitation within the environment.

Known false positives

  • False positives may occur, depending on the organization's size and the configuration of Okta.

MITRE ATT&CK coverage

TacticTechniques
Credential Access

Telemetry coverage

Rules detecting the same action

These rules filter on the same operation.

Rule body

name: Okta Suspicious Use of a Session Cookie
id: 71ad47d1-d6bd-4e0a-b35c-020ad9a6959e
version: 12
creation_date: '2024-04-17'
modification_date: '2026-05-13'
author: Scott Dermott, Felicity Robson, Okta, Michael Haag, Bhavin Patel, Splunk
status: production
type: Anomaly
description: The following analytic identifies suspicious use of a session cookie by detecting multiple client values (IP, User Agent, etc.) changing for the same Device Token associated with a specific user. It leverages policy evaluation events from successful authentication logs in Okta. This activity is significant as it may indicate an adversary attempting to reuse a stolen web session cookie, potentially bypassing authentication mechanisms. If confirmed malicious, this could allow unauthorized access to user accounts, leading to data breaches or further exploitation within the environment.
data_source:
    - Okta
search: |-
    `okta` eventType IN (policy.evaluate_sign_on) outcome.result IN (ALLOW, SUCCESS)
      | stats earliest(_time) as _time, values(client.ipAddress) as src_ip, values(client.userAgent.rawUserAgent) as user_agent, values(client.userAgent.os) as userAgentOS_list, values(client.geographicalContext.city) as city, values(client.userAgent.browser) as userAgentBrowser_list, values(device.os_platform) as okta_device_os, dc(client.userAgent.browser) as dc_userAgentBrowser, dc(client.userAgent.os) as dc_userAgentOS, dc(client.ipAddress) as dc_src_ip, values(outcome.reason) as reason values(dest) as dest
        BY debugContext.debugData.dtHash, user
      | where dc_src_ip>1 AND (dc_userAgentOS>1 OR dc_userAgentBrowser>1)
      | `okta_suspicious_use_of_a_session_cookie_filter`
how_to_implement: This detection utilizes logs from Okta Identity Management (IM) environments. It requires the ingestion of OktaIm2 logs through the Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
known_false_positives: False positives may occur, depending on the organization's size and the configuration of Okta.
references:
    - https://attack.mitre.org/techniques/T1539/
intermediate_findings:
    entities:
        - field: user
          type: user
          score: 20
          message: A user [$user$] is attempting to use a session cookie from multiple IP addresses or devices. Investigate further to determine if this was authorized.
analytic_story:
    - Suspicious Okta Activity
    - Okta Account Takeover
    - Scattered Lapsus$ Hunters
asset_type: Okta Tenant
mitre_attack_id:
    - T1539
product:
    - Splunk Enterprise
    - Splunk Enterprise Security
    - Splunk Cloud
category: application
security_domain: identity

Stages and Predicates

Stage 1: search

`okta` eventType IN (policy.evaluate_sign_on) outcome.result IN (ALLOW, SUCCESS)

Stage 2: stats

| stats earliest(_time) as _time, values(client.ipAddress) as src_ip, values(client.userAgent.rawUserAgent) as user_agent, values(client.userAgent.os) as userAgentOS_list, values(client.geographicalContext.city) as city, values(client.userAgent.browser) as userAgentBrowser_list, values(device.os_platform) as okta_device_os, dc(client.userAgent.browser) as dc_userAgentBrowser, dc(client.userAgent.os) as dc_userAgentOS, dc(client.ipAddress) as dc_src_ip, values(outcome.reason) as reason values(dest) as dest
    BY debugContext.debugData.dtHash, user

Stage 3: where

| where dc_src_ip>1 AND (dc_userAgentOS>1 OR dc_userAgentBrowser>1)

Stage 4: search

| `okta_suspicious_use_of_a_session_cookie_filter`

Indicators

These rows show field, operator, and value matches.