BigHugger
sk Skill · mukul975

hunting-saas-sso-token-abuse

Hunts for stolen-session and OAuth/PRT token replay (T1550.001) by correlating Microsoft Entra ID SigninLogs SessionId/UniqueTokenIdentifier fields and Okta System Log sso/session events to spot impossible travel, refresh-token reuse, and token use from anomalous ASNs. Use when hunting MFA-bypass via stolen cookies/tokens, investigating impossible-travel alerts, or scoping SaaS lateral movement after phishing.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
kustoPythonoktabashentra-idpass-the-cookietoken-theftoauthssospldetection-engineeringthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python