Skip to main content
Run any Skill in Manus
with one click

remediate-okta-session-kill

Stars3
Forks0
UpdatedJuly 9, 2026 at 18:17

Contain an Okta account takeover by revoking all active sessions and OAuth refresh tokens for the affected user. Consumes an OCSF 1.8 Detection Finding (class 2004) emitted by detect-okta-mfa-fatigue or detect-credential-stuffing-okta and calls the Okta Users API to revoke sessions, revoke OAuth tokens, and optionally force password reset. Every action is dry-run by default, deny-listed against break-glass / admin / service-account principals, and dual-audited (DynamoDB + KMS-encrypted S3 object). Use when the user mentions "kill Okta session," "revoke Okta tokens after MFA fatigue," "Okta session kill," "contain Okta credential stuffing," or "Okta account takeover response." Do NOT use for Entra / Azure AD, Google Workspace, AWS IAM, or GCP sessions — those have their own per-IdP remediation skills. Do NOT bypass the deny-list, run with --apply without an explicit human-approved incident window, explicit Okta org allow-list, or edit the audit trail by hand.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
8 files
SKILL.md
readonly