Skip to main content
Ejecuta cualquier Skill en Manus
con un clic

remediate-okta-session-kill

Estrellas3
Forks0
Actualizado9 de julio de 2026 a las 18:17

Contain an Okta account takeover by revoking all active sessions and OAuth refresh tokens for the affected user. Consumes an OCSF 1.8 Detection Finding (class 2004) emitted by detect-okta-mfa-fatigue or detect-credential-stuffing-okta and calls the Okta Users API to revoke sessions, revoke OAuth tokens, and optionally force password reset. Every action is dry-run by default, deny-listed against break-glass / admin / service-account principals, and dual-audited (DynamoDB + KMS-encrypted S3 object). Use when the user mentions "kill Okta session," "revoke Okta tokens after MFA fatigue," "Okta session kill," "contain Okta credential stuffing," or "Okta account takeover response." Do NOT use for Entra / Azure AD, Google Workspace, AWS IAM, or GCP sessions — those have their own per-IdP remediation skills. Do NOT bypass the deny-list, run with --apply without an explicit human-approved incident window, explicit Okta org allow-list, or edit the audit trail by hand.

Instalación

Instalar con Codex o Claude Copia este prompt, pégalo en Codex, Claude u otro asistente, y deja que revise la página de la skill y la instale por ti.

Explorador de archivos
8 archivos
SKILL.md
readonly