Skip to main content
Manus에서 모든 스킬 실행
원클릭으로

remediate-okta-session-kill

스타3
포크0
업데이트2026년 7월 9일 18:17

Contain an Okta account takeover by revoking all active sessions and OAuth refresh tokens for the affected user. Consumes an OCSF 1.8 Detection Finding (class 2004) emitted by detect-okta-mfa-fatigue or detect-credential-stuffing-okta and calls the Okta Users API to revoke sessions, revoke OAuth tokens, and optionally force password reset. Every action is dry-run by default, deny-listed against break-glass / admin / service-account principals, and dual-audited (DynamoDB + KMS-encrypted S3 object). Use when the user mentions "kill Okta session," "revoke Okta tokens after MFA fatigue," "Okta session kill," "contain Okta credential stuffing," or "Okta account takeover response." Do NOT use for Entra / Azure AD, Google Workspace, AWS IAM, or GCP sessions — those have their own per-IdP remediation skills. Do NOT bypass the deny-list, run with --apply without an explicit human-approved incident window, explicit Okta org allow-list, or edit the audit trail by hand.

설치

Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.

파일 탐색기
8 개 파일
SKILL.md
readonly