What problem does it solve?
This skill solves the critical gap where legacy security and compliance frameworks (NIST 800-53, ISO 27001, SOC 2, NIS2, DORA) were designed for pre-2020 network-centric environments and lack controls, evidence paths, and reporting structures for modern identity provider (IdP) threats, leaving security teams unable to properly detect, respond to, and document IdP tenant compromises from 2023-2026 attack patterns like Midnight Blizzard, Scattered Spider, and OAuth consent abuse.
Core Features & Use Cases
- Mid-2026 Threat Context: Deep coverage of real-world IdP incidents including Okta support-system breaches, Entra ID OAuth consent abuse, Auth0 management-API token leakage, and help-desk social engineering TTPs used by groups like Scattered Spider and Midnight Blizzard.
- Framework Gap Mapping: Explicit flags for where common compliance controls fail for IdP attacks, with direct references to framework control gaps for NIST, ISO, SOC 2, NIS2, DORA, and other global jurisdictional requirements.
- Structured 10-Phase Response Procedure: End-to-end workflow covering tenant ownership attestation, jurisdiction clock tracking, 90-day audit log collection, federated trust integrity checks, OAuth consent inventory, privileged role audits, and downstream SaaS telemetry sweeps.
- Regulatory Alignment: Built-in tracking for mandatory incident reporting deadlines including DORA 4-hour, NIS2 24-hour, GDPR 72-hour, NYDFS 72-hour, and AU NDB 30-day clocks.
- Use Case: A security team responding to an Entra ID tenant compromise can use this skill to pull audit logs, identify unauthorized OAuth consent grants, check for SAML signing key tampering, and generate a compliant incident assessment that satisfies multi-jurisdictional reporting requirements without relying on outdated control evidence.
Quick Start
Use the idp-incident-response skill to run a full IdP tenant compromise assessment for your Entra ID tenant, pulling 90 days of audit logs, checking federated trust integrity, and generating a jurisdiction-aligned incident report with all mandatory SLA deadlines.