Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

AN0339 (DET0120, T1531) cites a non-existent Okta System Log event type

オープン 初心者向け
#76 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
75/100
issue の種類
ドキュメント
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
python

調査の方向性

この issue は、検出戦略 DET0120 内の分析 AN0339 を指しています。まず、この分析と Okta イベントタイプを参照している関連する STIX データファイルを特定します。Okta イベントタイプカタログを確認して、正しいイベント名を確認します。存在しない user.lifecycle.delete の代わりに user.lifecycle.deactivate と user.lifecycle.delete.completed を使用するように引用を更新します。変更が ATT&CK テクニック T1531 の説明と一致していることを確認します。

索引モデルが issue の本文から書いたものです。

説明

While building a field-presence reference for Okta's System Log ahead of a detection project, I cross-checked the Okta-specific analytic under Detection Strategy DET0120 (T1531, Account Access Removal) against Okta's own primary documentation and found a citation error.

Analytic AN0339 (https://attack.mitre.org/detectionstrategies/DET0120/) reads:

Deletion or disablement of user accounts in platforms like Okta, Salesforce, or Zoom with anomalies in admin session attributes or mass actions within short duration.

Log source cited: User Account Modification (DC0010) via saas:okta with event types user.lifecycle.delete, user.account.lock.

user.lifecycle.delete does not exist as an Okta System Log event type. Checked directly against Okta's own event-types catalog (https://developer.okta.com/docs/reference/api/event-types/) and the management OpenAPI spec. The real, closed event types are:

  • user.lifecycle.deactivate — "Deactivate Okta user."
  • user.lifecycle.delete.completed — the actual completion event for a user deletion.

Separately, user.account.lock is real but likely the wrong event for this technique: its own documented description is "Auto-lock user account for Okta" — an automated security-policy lockout (e.g. repeated bad passwords), not a deliberate admin- or adversary-initiated account disablement, which is what T1531 describes. user.lifecycle.deactivate and/or user.lifecycle.delete.completed look like the semantically correct pairing for this technique; user.account.lock describes a different, benign-by-default event.

Happy to provide more detail if useful. Found this while researching Okta as a telemetry source for an AI-SOC detection pipeline, cross-checking every cited vendor field against primary docs rather than trusting a secondary description — this is the one place that check didn't hold up.

主要言語
Python
スター
677
フォーク
147
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

mitre-attack/attack-stix-data のほかの issue

mitre-attack/attack-stix-data の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。