CyberCLI
← All connectors

Okta

Coming soon Pro

Cloud Identity & Email

Every authentication, MFA challenge, and admin action — the credential-access keystone.

Okta homepage ↗

Dedicated identity provider. Okta's SystemLog API delivers every authentication, MFA challenge, group change, and admin action — the credential-access keystone for orgs that don't centralize on M365 or Workspace.

What it watches

  • Authentication events — success, failure, MFA challenges + denials
  • Impossible-travel + new-device sign-ins
  • Group + role changes, app assignments
  • Admin actions — policy, factor, and API-token changes
  • Suspicious-activity + ThreatInsight signals

MITRE ATT&CK coverage

Tactics this connector gives CyberCLI visibility into.

TA0001 · Initial Access TA0005 · Defense Evasion TA0006 · Credential Access TA0007 · Discovery
See the full coverage matrix →

What it helps you catch

Catches MFA fatigue / push-bombing by the pattern of repeated challenges before an approval.
Flags an admin granting themselves a role or minting an API token — privilege escalation inside the IdP.
Surfaces the impossible-travel sign-in that says a credential is already in the wrong hands.

What you'd see in CyberCLI

illustrative
CYCON 3 high Okta

Catches MFA fatigue / push-bombing by the pattern of repeated challenges before an approval.

Routed to Warden (triage) → Knight (detection) → Marshal (response) → Herald (notify)

⛓ every step hash-chained · replayable

Close more of the kill chain

Okta covers 4 of 14 ATT&CK tactics. Pair it with these to widen coverage:

How to connect

On the roadmap — not yet shipped

Okta is on the connector roadmap but not yet bundled. The plan above describes what we'll ingest + how it maps to MITRE; install instructions land when the connector pack ships.

Tell us you'd use it →  Pro tier customers get priority on connector prioritisation.

Guild roles it feeds
  • Warden (triage)
  • Knight (detection)
  • Marshal (response)
  • Herald (notify)
The Guild →
Sovereignty

Hybrid. Okta's SystemLog is pulled via API into your local SOC — identity telemetry correlated under your control.

Go deeper