logo

Leveraging CrowdStrike Falcon Against Attacks Targeting Okta Environments

ID: 6f161678-84aa-5860-b92e-f2a87e8f1c64

STIX ID: report--6f161678-84aa-5860-b92e-f2a87e8f1c64

Feed Name: Crowdstrike Blog

Date Published: 2025-01-21

Date Updated: 2026-04-27

Author: Tony Gore - Justin Schoenfeld

...
...

This report provides detection guidance for Okta-focused post-compromise activity, including identifying MFA push fatigue, persistence using the Okta Terrify toolkit, and abuse of delegate authority/Kerberos-based DesktopSSO. It includes concrete hunting queries, behavioral indicators (e.g., multiple auth_via_mfa events, enrollment ID anomalies, proof-of-possession usage), and a lower-fidelity user agent pattern to aid defenders in spotting suspicious authentication flows and attacker persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.