idp-incident-response

Run a 10-phase IdP tenant compromise assessment with jurisdiction clock tracking.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill idp-incident-response
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: idp-incident-response
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/idp-incident-response
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill idp-incident-response

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the critical gap where legacy security and compliance frameworks (NIST 800-53, ISO 27001, SOC 2, NIS2, DORA) were designed for pre-2020 network-centric environments and lack controls, evidence paths, and reporting structures for modern identity provider (IdP) threats, leaving security teams unable to properly detect, respond to, and document IdP tenant compromises from 2023-2026 attack patterns like Midnight Blizzard, Scattered Spider, and OAuth consent abuse.

Core Features & Use Cases

  • Mid-2026 Threat Context: Deep coverage of real-world IdP incidents including Okta support-system breaches, Entra ID OAuth consent abuse, Auth0 management-API token leakage, and help-desk social engineering TTPs used by groups like Scattered Spider and Midnight Blizzard.
  • Framework Gap Mapping: Explicit flags for where common compliance controls fail for IdP attacks, with direct references to framework control gaps for NIST, ISO, SOC 2, NIS2, DORA, and other global jurisdictional requirements.
  • Structured 10-Phase Response Procedure: End-to-end workflow covering tenant ownership attestation, jurisdiction clock tracking, 90-day audit log collection, federated trust integrity checks, OAuth consent inventory, privileged role audits, and downstream SaaS telemetry sweeps.
  • Regulatory Alignment: Built-in tracking for mandatory incident reporting deadlines including DORA 4-hour, NIS2 24-hour, GDPR 72-hour, NYDFS 72-hour, and AU NDB 30-day clocks.
  • Use Case: A security team responding to an Entra ID tenant compromise can use this skill to pull audit logs, identify unauthorized OAuth consent grants, check for SAML signing key tampering, and generate a compliant incident assessment that satisfies multi-jurisdictional reporting requirements without relying on outdated control evidence.

Quick Start

Use the idp-incident-response skill to run a full IdP tenant compromise assessment for your Entra ID tenant, pulling 90 days of audit logs, checking federated trust integrity, and generating a jurisdiction-aligned incident report with all mandatory SLA deadlines.

Frequently Asked Questions about idp-incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I respond to an Okta breach or Entra ID compromise?

A structured 10-phase IdP incident response procedure covers tenant ownership attestation, 90-day audit log collection, federated trust integrity checks, OAuth consent inventory, and privileged role audits for Okta and Entra ID tenants.

What compliance reporting deadlines apply to an identity provider incident?

Compliance reporting for IdP incidents requires tracking DORA 4-hour, NIS2 24-hour, GDPR 72-hour, NYDFS 72-hour, and AU NDB 30-day jurisdiction clocks to satisfy multi-jurisdictional regulatory reporting obligations.

How do I detect OAuth consent abuse and SAML token forgery in my tenant?

Detect OAuth consent abuse and SAML token forgery by pulling 90-day audit logs, inventorying consent grants, and checking federated trust integrity to identify Midnight Blizzard and Scattered Spider attack patterns.

Why do legacy security frameworks fail for modern IdP threats?

Legacy frameworks like NIST 800-53, ISO 27001, and SOC 2 lack controls and evidence paths for modern IdP threats because they were designed for pre-2020 network-centric environments, leaving gaps for 2023-2026 attack patterns.

Does this incident response procedure support Auth0 and Ping tenants?

The IdP incident response procedure explicitly supports Okta, Entra ID, Auth0, Ping, and OneLogin tenants, covering management-API token leakage and help-desk social engineering patterns used by threat groups.