Notifications
Clear all
Topic starter
16/07/2026 5:55 am
Just finished a trial of Panther and wanted to share something practical. I was testing the detection-as-code approach, specifically for our Okta environment.
I built a few detections for common threats like impossible travel and new device registration from a suspicious location. The YAML structure felt straightforward once I got the hang of it. I'm curious if others have built similar rules—did you run into any issues with the timing of the Okta log ingestion? I'm still learning the nuances of the platform.