Leveraging CrowdStrike Falcon Against Attacks Targeting Okta Environments
ID: 6f161678-84aa-5860-b92e-f2a87e8f1c64
STIX ID: report--6f161678-84aa-5860-b92e-f2a87e8f1c64
Feed Name: Crowdstrike Blog
This report provides detection guidance for Okta-focused post-compromise activity, including identifying MFA push fatigue, persistence using the Okta Terrify toolkit, and abuse of delegate authority/Kerberos-based DesktopSSO. It includes concrete hunting queries, behavioral indicators (e.g., multiple auth_via_mfa events, enrollment ID anomalies, proof-of-possession usage), and a lower-fidelity user agent pattern to aid defenders in spotting suspicious authentication flows and attacker persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
