logo

Okta for Red Teamers

ID: d3415085-d256-5216-8414-7a027f71ada6

STIX ID: report--d3415085-d256-5216-8414-7a027f71ada6

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This technical write-up details multiple practical attack techniques against Okta-based identity infrastructures: abusing Delegated Authentication via Kerberos tickets (including TGS/Silver Ticket use), extracting and abusing Okta AD Agent tokens (DPAPI decryption and internal API calls) to capture or forge authentication, provisioning a fake AD connector using administrative API flows, and deploying a malicious SAML Identity Provider to impersonate users. The post provides commands, API call examples, and an attacker workflow useful for red teams — and relevant to defenders for detection and hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.