Okta for Red Teamers
ID: d3415085-d256-5216-8414-7a027f71ada6
STIX ID: report--d3415085-d256-5216-8414-7a027f71ada6
Feed Name: TrustedSec blog
This technical write-up details multiple practical attack techniques against Okta-based identity infrastructures: abusing Delegated Authentication via Kerberos tickets (including TGS/Silver Ticket use), extracting and abusing Okta AD Agent tokens (DPAPI decryption and internal API calls) to capture or forge authentication, provisioning a fake AD connector using administrative API flows, and deploying a malicious SAML Identity Provider to impersonate users. The post provides commands, API call examples, and an attacker workflow useful for red teams — and relevant to defenders for detection and hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
