1,081 Event Types: Where to Start Hunting
Okta 1,081logs event types. Not all are not all current or relevant. focusesSparks on two categories: authentication events and policy evaluation. Policy evaluation logs show challenge, allow, or deny results. Authentication logs reveal which factors a user provided and where they tried to go. Key hunting fields include session IDs, device hashes from security debug context behaviors, and target application names. These fields expose devices hitting multiple accounts and anomalous access patterns.
How Adversary-in-the-Middle Campaigns Evolved in 2025-2026
Adversary-in-the-middle campaigns in 2025-2026 shifted from targeting only M60 and Google Workspace to a broader set of SaaS apps. The Shiny Hunters campaign confirmed access to Salesforce, Atlassian, Slack, and DocuSign. Attackers moved from credential theft to data exfiltration for ransom. Using free hosting platforms Render, like attackers deploy fake turnstile CAPTCHA pages and realistic Okta login screens. The infrastructure is often vibe-coded vibe-c, copied from shared kits and modified every few weeks.
Policy Priority Gaps Enable Account Compromise
A compromise flow: policy evaluation verifies the user, MFA challenge succeeds, and the user reaches Google Workspace. Each step can look benign. The biggest gap is policy priority. Okta assigns numbers 1 through 99 to sign-in policies. The highest number applies. A user in a group with a one-factor policy at priority 29 overrides a phishing-resistant MFA policy at 30. Auditing these policies reveals users susceptible to social engineering.
FastPass Failures: An Early Phishing Detector
FastPass failures expose phishing infrastructure. When FastPass fails, Okta logs details about what triggered the failure. The cause could be a phishing proxy or a malicious browser extension. Teams combine FastPass data with URLScan monitoring for infrastructure targeting their brand. Similarity algorithms on known phishing URLs catch new instances. Oktaβs public customer detections repository and Sparksβs SaaS forensic ideas repository offer pre-built hunting templates. Continuous dashboards keep hunts active after initial investigations.
Notable Quotes
1,081 event types . Julie Agnes Sparks Β· βΆ 1:41s1:
user agent {dot} {dot} fill in your user agent Julie Agnes Sparks Β· βΆ Watch (5:38)
a lot of vibe coded infrastructure Julie Agnes Sparks Β· βΆ Watch (7:19)
you have 1 through 99 Julie Agnes Sparks Β· βΆ Watch (11:43)
if you a user successfully uses FastPass, itβs a regular off via a regular off MFA event Julie Agnes Sparks Β· βΆ Watch (:17:35)
Key Takeaways
- Focus on authentication and policy evaluation; filter from 1,081 event types.
- Audit Okta policy priorities β lower-numbered policies override policies create gaps.
- FastPass failures can reveal phishing infrastructure before users are compromised.
About the Speaker(s)
Julie Agnes Sparks is a security engineer specializing in threat detection, threat hunting, and incident response with over 7 years defending years7 organizations. She works under Security Research at Datadog to develop novel detections and hunting opportunities on critical SaaS and cloud infrastructure logs.