Log sources › saas:okta
saas:okta
Inverted view: what can be detected if this is the log you have. Identity Provider, SaaS
17
channels
16
analytics
16
techniques
55
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Conditional Access policy rule modified or MFA requirement disabled |
DC0038 Application Log Content | AN0088 | 1 |
Federation configuration update or signing certificate change |
DC0038 Application Log Content | AN0818 | 1 |
MFAChallengeIssued |
DC0038 Application Log Content | AN0453 | 1 |
Sign-in logs / audit events |
DC0002 User Account Authentication | AN1546 | 1 |
System API Call: user.read, group.read |
DC0038 Application Log Content | AN1090 | 1 |
Unusual OAuth app requesting message-read scopes for Slack/Teams/Jira |
DC0002 User Account Authentication | AN0310 | 1 |
User Attribute Modified / Role Assignment Changed |
DC0010 User Account Modification | AN0268 | 1 |
User Enumeration Events |
DC0013 User Account Metadata | AN1616 | 1 |
User lifecycle events |
DC0013 User Account Metadata | AN1079 | 1 |
WebUI access to administrator dashboard |
DC0038 Application Log Content | AN0809 | 1 |
policy.rule.update;system.log.disable;admin.role.assign |
DC0038 Application Log Content | AN2042 | 1 |
session.impersonation.start |
DC0002 User Account Authentication | AN0202 | 1 |
session.token.reuse |
DC0067 Logon Session Creation | AN1406 | 1 |
user.account.reset_password; user.mfa.factor.activate; app.oauth2.authorize |
DC0002 User Account Authentication | AN2034 | 1 |
user.authentication.sso |
DC0088 Logon Session Metadata | AN1503 | 1 |
user.lifecycle.delete, user.account.lock |
DC0010 User Account Modification | AN0339 | 1 |
user.session.start |
DC0067 Logon Session Creation | AN0809 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1036.010 Masquerade Account Name | stealth | 0 | 0 |
| T1078 Valid Accounts | stealth, persistence, privilege escalation, initial access | 56 | 46 |
| T1078.004 Cloud Accounts | stealth, persistence, privilege escalation, initial access | 41 | 1 |
| T1087 Account Discovery | discovery | 16 | 6 |
| T1087.004 Cloud Account | discovery | 3 | 0 |
| T1098 Account Manipulation | persistence, privilege escalation | 34 | 2 |
| T1531 Account Access Removal | impact | 9 | 1 |
| T1538 Cloud Service Dashboard | discovery | 0 | 0 |
| T1539 Steal Web Session Cookie | credential access | 2 | 0 |
| T1550.004 Web Session Cookie | lateral movement | 0 | 0 |
| T1552.008 Chat Messages | credential access | 0 | 0 |
| T1556.007 Hybrid Identity | defense impairment, persistence, credential access | 0 | 0 |
| T1556.009 Conditional Access Policies | defense impairment, persistence, credential access | 0 | 0 |
| T1621 Multi-Factor Authentication Request Generation | credential access | 2 | 0 |
| T1684 Social Engineering | stealth | 0 | 0 |
| T1687 Exploitation for Defense Impairment | defense impairment | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2012-0767 | Adobe Flash Player | T1098 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1078 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1078 | Mapped |
| CVE-2021-20035 | SonicWall SMA100 Appliances | T1078 | Mapped |
| CVE-2021-22894 | Ivanti Pulse Connect Secure | T1078 | Mapped |
| CVE-2021-22899 | Ivanti Pulse Connect Secure | T1078 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1098 | Mapped |
| CVE-2021-36934 | Microsoft Windows | T1078 | Mapped |
| CVE-2021-41379 | Microsoft Windows | T1078 | Mapped |
| CVE-2021-42321 | Microsoft Exchange | T1078 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1087 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1078 | Mapped |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1078 | Mapped |
| CVE-2022-21919 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-22047 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-22718 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-22948 | VMware vCenter Server | T1078 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1078 | Mapped |
| CVE-2022-24521 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1078 | Mapped |
| CVE-2022-26904 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-37969 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-41073 | Microsoft Windows | T1078 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1078 T1087 | Mapped |
| CVE-2022-41125 | Microsoft Windows | T1078 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1078 | Mapped |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | T1078 | Mapped |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense | T1078 | Mapped |
| CVE-2023-20273 | Cisco Cisco IOS XE Web UI | T1078 | Mapped |
| CVE-2023-20867 | VMware Tools | T1078 | Mapped |
| CVE-2023-21674 | Microsoft Windows | T1078 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1078 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1078 | Stale |
| CVE-2023-23397 | Microsoft Office | T1078 | Mapped |
| CVE-2023-27524 | Apache Superset | T1078 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1087 | Mapped |
| CVE-2023-28229 | Microsoft Windows CNG Key Isolation Service | T1078 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1078 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1531 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1078 | Mapped |
| CVE-2023-41179 | Trend Micro Apex One and Worry-Free Business Security | T1078 | Mapped |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | T1078 | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | T1087 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1078 | Mapped |
| CVE-2024-20399 | Cisco NX-OS | T1078 | Mapped |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | T1078 | Mapped |
| CVE-2024-37085 | VMware ESXi | T1078 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1078.004 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1078 | Mapped |
| CVE-2024-57968 | Advantive VeraCore | T1078 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | T1078 | Mapped |
| CVE-2025-31161 | CrushFTP CrushFTP | T1078 | Mapped |