kevmap

Log sources › saas:okta

saas:okta

Inverted view: what can be detected if this is the log you have. Identity Provider, SaaS

17
channels
16
analytics
16
techniques
55
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Conditional Access policy rule modified or MFA requirement disabled DC0038 Application Log Content AN0088 1
Federation configuration update or signing certificate change DC0038 Application Log Content AN0818 1
MFAChallengeIssued DC0038 Application Log Content AN0453 1
Sign-in logs / audit events DC0002 User Account Authentication AN1546 1
System API Call: user.read, group.read DC0038 Application Log Content AN1090 1
Unusual OAuth app requesting message-read scopes for Slack/Teams/Jira DC0002 User Account Authentication AN0310 1
User Attribute Modified / Role Assignment Changed DC0010 User Account Modification AN0268 1
User Enumeration Events DC0013 User Account Metadata AN1616 1
User lifecycle events DC0013 User Account Metadata AN1079 1
WebUI access to administrator dashboard DC0038 Application Log Content AN0809 1
policy.rule.update;system.log.disable;admin.role.assign DC0038 Application Log Content AN2042 1
session.impersonation.start DC0002 User Account Authentication AN0202 1
session.token.reuse DC0067 Logon Session Creation AN1406 1
user.account.reset_password; user.mfa.factor.activate; app.oauth2.authorize DC0002 User Account Authentication AN2034 1
user.authentication.sso DC0088 Logon Session Metadata AN1503 1
user.lifecycle.delete, user.account.lock DC0010 User Account Modification AN0339 1
user.session.start DC0067 Logon Session Creation AN0809 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1036.010 Masquerade Account Namestealth00
T1078 Valid Accountsstealth, persistence, privilege escalation, initial access5646
T1078.004 Cloud Accountsstealth, persistence, privilege escalation, initial access411
T1087 Account Discoverydiscovery166
T1087.004 Cloud Accountdiscovery30
T1098 Account Manipulationpersistence, privilege escalation342
T1531 Account Access Removalimpact91
T1538 Cloud Service Dashboarddiscovery00
T1539 Steal Web Session Cookiecredential access20
T1550.004 Web Session Cookielateral movement00
T1552.008 Chat Messagescredential access00
T1556.007 Hybrid Identitydefense impairment, persistence, credential access00
T1556.009 Conditional Access Policiesdefense impairment, persistence, credential access00
T1621 Multi-Factor Authentication Request Generationcredential access20
T1684 Social Engineeringstealth00
T1687 Exploitation for Defense Impairmentdefense impairment00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2012-0767Adobe Flash Player T1098 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1078 Mapped
CVE-2019-13608Citrix StoreFront Server T1078 Mapped
CVE-2021-20035SonicWall SMA100 Appliances T1078 Mapped
CVE-2021-22894Ivanti Pulse Connect Secure T1078 Mapped
CVE-2021-22899Ivanti Pulse Connect Secure T1078 Mapped
CVE-2021-32030ASUS Routers T1098 Mapped
CVE-2021-36934Microsoft Windows T1078 Mapped
CVE-2021-41379Microsoft Windows T1078 Mapped
CVE-2021-42321Microsoft Exchange T1078 Mapped
CVE-2021-44515Zoho Desktop Central T1087 Mapped
CVE-2022-1040Sophos Firewall T1078 Mapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1078 Mapped
CVE-2022-21919Microsoft Windows T1078 Mapped
CVE-2022-21999Microsoft Windows T1078 Mapped
CVE-2022-22047Microsoft Windows T1078 Mapped
CVE-2022-22718Microsoft Windows T1078 Mapped
CVE-2022-22948VMware vCenter Server T1078 Mapped
CVE-2022-23131Zabbix Frontend T1078 Mapped
CVE-2022-24521Microsoft Windows T1078 Mapped
CVE-2022-26500Veeam Backup & Replication T1078 Mapped
CVE-2022-26904Microsoft Windows T1078 Mapped
CVE-2022-37969Microsoft Windows T1078 Mapped
CVE-2022-41073Microsoft Windows T1078 Mapped
CVE-2022-41082Microsoft Exchange Server T1078 T1087 Mapped
CVE-2022-41125Microsoft Windows T1078 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1078 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1078 Mapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense T1078 Mapped
CVE-2023-20273Cisco Cisco IOS XE Web UI T1078 Mapped
CVE-2023-20867VMware Tools T1078 Mapped
CVE-2023-21674Microsoft Windows T1078 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1078 Mapped
CVE-2023-22952SugarCRM Multiple Products T1078 Stale
CVE-2023-23397Microsoft Office T1078 Mapped
CVE-2023-27524Apache Superset T1078 Mapped
CVE-2023-27532Veeam Backup & Replication T1087 Mapped
CVE-2023-28229Microsoft Windows CNG Key Isolation Service T1078 Mapped
CVE-2023-28252Microsoft Windows T1078 Mapped
CVE-2023-34362Progress MOVEit Transfer T1531 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1078 Mapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business Security T1078 Mapped
CVE-2023-46805Ivanti Connect Secure and Policy Secure T1078 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1078 Mapped
CVE-2024-20399Cisco NX-OS T1078 Mapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons T1078 Mapped
CVE-2024-37085VMware ESXi T1078 Mapped
CVE-2024-53704SonicWall SonicOS T1078.004 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1078 Mapped
CVE-2024-57968Advantive VeraCore T1078 Mapped
CVE-2025-24016Wazuh Wazuh Server T1078 Mapped
CVE-2025-31161CrushFTP CrushFTP T1078 Mapped