detect-credential-stuffing-okta
Installation
SKILL.md
detect-credential-stuffing-okta
Attack pattern
Credential stuffing is the pattern where an attacker replays leaked username/password pairs across Okta until one works. Password spraying is the adjacent pattern where a small number of common passwords are tried across many users. In Okta System Log terms, both look like:
- a burst of
user.session.start/user.authentication.auth/user.authentication.sso/user.authentication.auth_via_mfaevents withoutcome.result: FAILURE(OCSFstatus_id = 2) against one user - followed by a successful sign-in (OCSF
status_id = 1) inside the same window - often from multiple distinct source IPs, indicating a botnet or proxy rotation