Skip to content

feat: Add Okta OCSF parser support and enhance M365 collaboration par…#73

Merged
natesmalley merged 1 commit intonatesmalley:mainfrom
jmorascalyr:improve-finance-mfa
Feb 21, 2026
Merged

feat: Add Okta OCSF parser support and enhance M365 collaboration par…#73
natesmalley merged 1 commit intonatesmalley:mainfrom
jmorascalyr:improve-finance-mfa

Conversation

@jmorascalyr
Copy link
Collaborator

…ser field mappings

  • Added okta_ocsf_logs parser to SCENARIO_SOURCE_TO_PARSER and SOURCETYPE_MAP_OVERRIDES mappings
  • Updated Finance Employee MFA Fatigue Attack scenario to use okta_ocsf_logs instead of okta_authentication
  • Added okta_ocsf_logs to JSON_PRODUCTS list for JSON format handling
  • Rewrote okta_ocsf_logs parser with proper JSON formatting and OCSF field mappings (actor.user, src_endpoint, http_request, activity_name, status

…ser field mappings

- Added okta_ocsf_logs parser to SCENARIO_SOURCE_TO_PARSER and SOURCETYPE_MAP_OVERRIDES mappings
- Updated Finance Employee MFA Fatigue Attack scenario to use okta_ocsf_logs instead of okta_authentication
- Added okta_ocsf_logs to JSON_PRODUCTS list for JSON format handling
- Rewrote okta_ocsf_logs parser with proper JSON formatting and OCSF field mappings (actor.user, src_endpoint, http_request, activity_name, status
@natesmalley natesmalley merged commit 3c1f457 into natesmalley:main Feb 21, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants