From 249d3198d33dd723d5554372162c2bea191f9213 Mon Sep 17 00:00:00 2001 From: Austin Songer Date: Sun, 12 Sep 2021 20:27:45 -0500 Subject: [PATCH] Create okta_application_sign-on_policy_modified_or_deleted.yml --- ...ion_sign-on_policy_modified_or_deleted.yml | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 rules/cloud/okta/okta_application_sign-on_policy_modified_or_deleted.yml diff --git a/rules/cloud/okta/okta_application_sign-on_policy_modified_or_deleted.yml b/rules/cloud/okta/okta_application_sign-on_policy_modified_or_deleted.yml new file mode 100644 index 000000000..47fd37e7e --- /dev/null +++ b/rules/cloud/okta/okta_application_sign-on_policy_modified_or_deleted.yml @@ -0,0 +1,22 @@ +title: Okta Application Sign-On Policy Modified or Deleted +id: Application Sign-On Policy +description: Detects when an application Sign-on Policy is modified or deleted. +author: Austin Songer +status: experimental +date: 2021/09/12 +references: + - https://developer.okta.com/docs/reference/api/system-log/ + - https://developer.okta.com/docs/reference/api/event-types/ +logsource: + service: okta +detection: + selection: + eventtype: + - application.policy.sign_on.update + - application.policy.sign_on.rule.delete + condition: selection +level: medium +tags: + - attack.impact +falsepositives: + - Unknown