New Detections: AWS CloudTrail and Okta Identity Threats
New Release
We have added 16 new detections: 13 AWS CloudTrail rules and 3 Okta identity rules, all mapped to MITRE ATT&CK.
The AWS CloudTrail detections identify unauthorized and anomalous activity across your AWS accounts, including malicious IAM users and groups, ECS credential harvesting, S3 Batch operations used to copy data to unexpected buckets, multi-region Amazon Bedrock model invocation, changes to SSO and identity provider configuration, and AWS Transfer Family server creation.
The Okta detections surface identity threats that often precede account takeover: repeated login failures, fallback to weak MFA factors, and MFA session and IP mismatches.
See the full list of our detections here.