remediate-okta-session-kill

Installation
SKILL.md

remediate-okta-session-kill

What this closes

Pair skill for:

Together those form the first shipped detect → act → audit → re-verify loop in the repo. A finding flows in (stdin OCSF 2004); this skill plans the containment (dry-run); an approver opts in with --apply; the Okta API calls run; the audit trail is dual-written. The same skill then runs in --reverify mode against the same finding to confirm the user has zero active sessions and zero OAuth refresh tokens — emitting a remediation_verification record (and, on DRIFT, a paired OCSF Detection Finding via the shared _shared/remediation_verifier.py contract) so the loop closes through the same SIEM/SOAR pipeline as every other finding.

Attack pattern it responds to

Any Okta account takeover where the attacker has an active session or token. The standard containment is:

  1. Revoke all active Okta sessions for the user → attacker is logged out
  2. Revoke all OAuth refresh tokens → attacker cannot silently re-auth
  3. (Optional) Expire password → force re-enrollment on next login
Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
remediate-okta-session-kill — msaad00/cloud-ai-security-skills