remediate-workspace-session-kill
Installation
SKILL.md
remediate-workspace-session-kill
What this closes
Pair skill for detect-google-workspace-suspicious-login — provider-marked suspicious Workspace login or repeated failures followed by success (MITRE ATT&CK T1110 Brute Force + T1078 Valid Accounts).
Closes #155 phase 4 (tracking issue: #312). After this lands, the closed-loop coverage matrix flips the Workspace row red→green. Ratio goes 7/11 → 8/11.
Why sign-out + force-password-change (not user.suspend)
Suspending the user breaks legitimate work for the legitimate owner. Sign-out + force-password-change is the standard Workspace account-takeover containment:
- Kills the attacker's existing session tokens immediately (revokes web/mobile auth)
- Requires the legitimate user to re-authenticate before regaining access
- Recovery path is owned by the user (password reset via recovery phone/email or admin assist)
Same containment philosophy as remediate-okta-session-kill.