Skip to content

Cloned login page detected
Webhook

Request

Security
X-Signature
Headers
X-Signaturestringrequired
Example:X-Signature: t=1492774577,v1=5257a869...
Bodyapplication/json

A cloned login page detected event occurred.

versionstring

The version of the event.

Example:"1"
idstring, (uuid)

The unique identifier for the event. This can be used as an idempotency key.

Example:"c478966c-f927-411c-b919-179832d3d50c"
tenantIdstring, (uuid)

The unique identifier of the tenant the event belongs to.

Example:"4f9d2e7a-1b3c-4d5e-8f6a-7c8b9d0e1f2a"
timestampinteger

When the event occurred, formatted as a UNIX timestamp (in seconds).

Example:1698604061
categorystring

The category of the event.

Value:"CONTROL"
descriptionstring

The description of the event. Note: this is subject to change and should not be used to match on this object.

Example:"john@company.com visited https://evil.com/okta.php which is a clone of a Okta login page"
objectstring

The object that was created.

Value:"CLONED_LOGIN_PAGE_DETECTED"
friendlyNamestring

The friendly name of this object. Note: this is subject to change and should not be used to match on this object.

Example:"Cloned login page detected"
newobject(Cloned login page detected)

Cloned login page detected event details.

Payload
{ "version": "1", "id": "c478966c-f927-411c-b919-179832d3d50c", "tenantId": "4f9d2e7a-1b3c-4d5e-8f6a-7c8b9d0e1f2a", "timestamp": 1698604061, "category": "CONTROL", "description": "john@company.com visited https://evil.com/okta.php which is a clone of a Okta login page", "object": "CLONED_LOGIN_PAGE_DETECTED", "friendlyName": "Cloned login page detected", "new": { "employee": { "id": "2a2197de-ad2c-47e4-8dcb-fb0f04cf83e0", "email": "john.hill@example.com", "firstName": "John", "lastName": "Hill", "department": "Security Engineering", "location": "New York", "licensed": true, "chatopsEnabled": true, "creationTimestamp": 1698669223 }, "mode": "OFF", "clonedLoginPageType": "OKTA", "clonedLoginPageUrls": [ "https://login.okta.com" ], "url": "https://evil.com/okta.php", "matchedUrl": "https://evil.com/phishing", "referrerUrl": "https://statics.teams.cdn.office.net/", "sourceIpAddress": "8.158.25.38", "browser": "CHROME", "os": "MACOS", "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 Edge/16.16299", "action": "DISPLAYED", "indicator": "INDICATOR_01" } }

Responses

Return any 2XX status to indicate that the data was received successfully