Files
blue-team-tools/rules/cloud/okta/okta_api_token_created.yml
T

24 lines
566 B
YAML
Raw Normal View History

2021-09-12 20:14:27 -05:00
title: Okta API Token Created
id: 19951c21-229d-4ccb-8774-b993c3ff3c5c
description: Detects when a API token is created
2021-09-22 19:51:31 -05:00
author: Austin Songer @austinsonger
2021-09-12 19:47:21 -05:00
status: experimental
2021-09-12 20:14:27 -05:00
date: 2021/09/12
2021-09-22 19:53:36 -05:00
modified: 2021/09/22
2021-09-12 19:47:21 -05:00
references:
- https://developer.okta.com/docs/reference/api/system-log/
- https://developer.okta.com/docs/reference/api/event-types/
logsource:
2021-11-14 10:58:26 +01:00
product: okta
2021-09-12 19:47:21 -05:00
service: okta
detection:
selection:
2021-09-12 20:14:27 -05:00
eventtype: system.api_token.create
2021-09-12 19:47:21 -05:00
condition: selection
level: medium
tags:
2021-09-12 20:14:27 -05:00
- attack.persistence
2021-09-12 19:47:21 -05:00
falsepositives:
2021-09-12 20:14:27 -05:00
- Unknown
2021-09-12 23:34:08 -05:00