You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rules: Okta - First Seen Client ID/ASN combo in successful OIDC token grant
Description
This signal looks for a new Client ID value ( mapped to the user_username field ) and ASN combination being issued an OIDC token, excluding the Okta Browser Plugin and Okta Dashboard. Use the Okta admin portal and look at the "Applications" section to cross-reference the Client ID value - ensure that the IP address that is requesting the token is known and that this operation is expected and authorized.
Additional Details
Detail
Value
Type
First Seen
Category
Defense Evasion
Apply Risk to Entities
user_username
Signal Name
Okta - First Seen Client ID/ASN combo in successful OIDC token grant for{{user_username}} from ASN {{srcDevice_ip_asnNumber}}
Summary Expression
Okta - First Seen Client ID in successful OIDC token grant for Client ID:{{user_username}} from {{device_ip}}