detect-credential-stuffing-okta

Installation
SKILL.md

detect-credential-stuffing-okta

Attack pattern

Credential stuffing is the pattern where an attacker replays leaked username/password pairs across Okta until one works. Password spraying is the adjacent pattern where a small number of common passwords are tried across many users. In Okta System Log terms, both look like:

  • a burst of user.session.start / user.authentication.auth / user.authentication.sso / user.authentication.auth_via_mfa events with outcome.result: FAILURE (OCSF status_id = 2) against one user
  • followed by a successful sign-in (OCSF status_id = 1) inside the same window
  • often from multiple distinct source IPs, indicating a botnet or proxy rotation
Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
detect-credential-stuffing-okta — msaad00/cloud-ai-security-skills