LoFP LoFP / t1078.004

t1078.004

TitleTags
a legitimate new admin account being created
a non malicious user is unaware of the proper process
a self-hosted runner is automatically removed from github if it has not connected to github actions for more than 14 days.
account disabled or blocked in error
actual admin using pim.
administrator adding a legitimate temporary access pass
allowed administrative activities.
allowed self-hosted runners changes in the environment.
an ephemeral self-hosted runner is automatically removed from github if it has not connected to github actions for more than 1 day.
automated processes using tools like terraform may trigger this alert.
automation account has been blocked or disabled
aws tasks that require aws account root user credentials https://docs.aws.amazon.com/general/latest/gr/aws_tasks-that-require-root.html
deletions by unfamiliar users should be investigated. if the behavior is known and expected, it can be exempted from the rule.
if this was approved by system administrator or confirmed user action.
if this was approved by system administrator.
known legacy accounts
legit administrative pim setting configuration changes
legitimate administrative actions by authorized system administrators could cause this alert. verify the user identity, user agent, and hostname to ensure they are expected.
legitimate logins
legitimate user wrong password attempts.
legtimate administrator actions of adding members from a role
misconfigured systems
service account misconfigured
this detection cloud be noisy depending on the environment. it is recommended to keep a check on the new secrets when created and validate the \"actor\".
unknown
unlikely
user has been put in acception group so they can use legacy authentication
users actually login but miss-click into the deny button when mfa prompt.
valid usage of s3 browser for iam loginprofile listing and/or creation
valid usage of s3 browser for iam user and/or accesskey creation
valid usage of s3 browser with accidental creation of default inline iam policy without changing default s3 bucket name placeholder value
vulnerability scanners
when an admin begins using the admin console and one of okta's heuristics incorrectly identifies the behavior as being unusual.
when and administrator is making legitimate appid uri configuration changes to an application. this should be a planned event.
when and administrator is making legitimate uri configuration changes to an application. this should be a planned event.