Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

How to detect MFA spamming with Falco

Blog post from Sysdig

Post Details
Company
Date Published
Author
Crystal Morin
Word Count
1,107
Company Posts That Month
17
Language
English
Hacker News Points
-
Post removed?
No
Summary

Falco has expanded its capabilities to detect multi-factor authentication (MFA) spamming, a technique used by groups like Lapsus$ to gain unauthorized access to systems by overwhelming users with repeated login requests. This method, also known as MFA fatigue, was employed in the high-profile Uber cybersecurity incident, emphasizing the importance of vigilance against social engineering attacks. Falco, widely recognized for its runtime security in Linux and Kubernetes environments, has developed an Okta plugin to monitor and alert on unusual MFA activities, such as excessive denies or failures in Okta logs. This tool helps organizations take preventive measures by generating alerts when suspicious patterns occur, thus enhancing their defense mechanisms against credential-based attacks. Despite robust security protocols at companies like Uber, the incident underscores the persistent threat of social engineering attacks and the need for continuous improvement in security practices, including proper management of access credentials and anomaly detection.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 5 886 67 34 +149%
Kubernetes 1 1,435 155 59 +20%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.