LoFP LoFP / legitimate creation of an api token by authorized users

Techniques

Sample rules

Okta API Token Created

Description

Detects when a API token is created

Detection logic

condition: selection
selection:
  eventtype: system.api_token.create