AN0339 (DET0120, T1531) cites a non-existent Okta System Log event type
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 75/100
- issue の種類
- ドキュメント
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- python
調査の方向性
この issue は、検出戦略 DET0120 内の分析 AN0339 を指しています。まず、この分析と Okta イベントタイプを参照している関連する STIX データファイルを特定します。Okta イベントタイプカタログを確認して、正しいイベント名を確認します。存在しない user.lifecycle.delete の代わりに user.lifecycle.deactivate と user.lifecycle.delete.completed を使用するように引用を更新します。変更が ATT&CK テクニック T1531 の説明と一致していることを確認します。
索引モデルが issue の本文から書いたものです。
説明
While building a field-presence reference for Okta's System Log ahead of a detection project, I cross-checked the Okta-specific analytic under Detection Strategy DET0120 (T1531, Account Access Removal) against Okta's own primary documentation and found a citation error.
Analytic AN0339 (https://attack.mitre.org/detectionstrategies/DET0120/) reads:
Deletion or disablement of user accounts in platforms like Okta, Salesforce, or Zoom with anomalies in admin session attributes or mass actions within short duration.
Log source cited: User Account Modification (DC0010) via saas:okta with event types user.lifecycle.delete, user.account.lock.
user.lifecycle.delete does not exist as an Okta System Log event type. Checked directly against Okta's own event-types catalog (https://developer.okta.com/docs/reference/api/event-types/) and the management OpenAPI spec. The real, closed event types are:
user.lifecycle.deactivate— "Deactivate Okta user."user.lifecycle.delete.completed— the actual completion event for a user deletion.
Separately, user.account.lock is real but likely the wrong event for this technique: its own documented description is "Auto-lock user account for Okta" — an automated security-policy lockout (e.g. repeated bad passwords), not a deliberate admin- or adversary-initiated account disablement, which is what T1531 describes. user.lifecycle.deactivate and/or user.lifecycle.delete.completed look like the semantically correct pairing for this technique; user.account.lock describes a different, benign-by-default event.
Happy to provide more detail if useful. Found this while researching Okta as a telemetry source for an AI-SOC detection pipeline, cross-checking every cited vendor field against primary docs rather than trusting a secondary description — this is the one place that check didn't hold up.
- 主要言語
- Python
- スター
- 677
- フォーク
- 147
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
mitre-attack/attack-stix-data のほかの issue
-
難易度 4/5 3〜5日 初心者へのやさしさ 20/100
-
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
-
難易度 3/5 1〜2日 初心者へのやさしさ 38/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 45/100
-
Inconsistent External References for MITRE ATT&CK ICS Techniques (12 affected entries)再び着手できるかも @seansica が 305 日前に担当しましたが、オープン中のプルリクエストはありません。 オープン
mitre-attack/attack-stix-data#63 · 担当者 1 名 ·
mitre-attack/attack-stix-data の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
メンテナーはふだん 1 日以内に返信
-
enhancement good first issue Stellar Wave trivial
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
StellarCanary/ProtocolCanary-Fixtures#258 ·
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
IBM/ai-atlas-nexus#295 ·
メンテナーはふだん 6 日以内に返信
-
github_actions
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
Hochfrequenz/aibap.mcp#578 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
mishraprafful/multihull#150 ·
メンテナーはふだん 1 日以内に返信