Supported Indicator Types
Configuration
Set your Okta credentials in the.env file:
Okta API tokens can be created in the Okta admin console under Security → API → Tokens. Use a service account with read-only permissions.
Extracted Fields
Malice Rules
Okta enrichment doesn’t set malice verdicts by default — it provides identity context rather than threat intelligence. The malice verdict for account indicators is typically driven by the overall investigation context rather than the identity lookup alone. You can configure custom malice rules if needed:Cache TTL
Account Matching
The Okta provider matches account indicators by:- Email address (
user@company.com) - Username (
jsmith) - Okta user ID

