Skip to content
Notifications
Clear all

Just made a set of detections for common Okta threats. Sharing the YAML.

1 Posts
1 Users
0 Reactions
1 Views
(@juliep)
Trusted Member
Joined: 1 week ago
Posts: 51
Topic starter   [#5039]

Just finished a trial of Panther and wanted to share something practical. I was testing the detection-as-code approach, specifically for our Okta environment.

I built a few detections for common threats like impossible travel and new device registration from a suspicious location. The YAML structure felt straightforward once I got the hang of it. I'm curious if others have built similar rules—did you run into any issues with the timing of the Okta log ingestion? I'm still learning the nuances of the platform.



   
Quote