What problem does it solve?
Enables security teams to identify and map Okta-as-IdP attack surfaces across tenants, enumerate potential user and MFA configurations, and assess post-compromise exposure within enterprise environments.
Core Features & Use Cases
- Tenant discovery and enumeration across Okta domains (e.g., tenant.okta.com, tenant.okta-emea.com, oktapreview.com) to identify attack surfaces.
- MFA factor analysis and attack-chain mapping (push fatigue, SMS, TOTP, and other factors) to prioritize testing vectors.
- Post-compromise admin API surface checks (session tokens, admin endpoints, and federation misconfigurations) across federated apps.
- Use Case: If recon reveals an Okta IdP, load the Okta attack chain to plan authenticated-access tests and risk-based remediation.
Quick Start
Describe your target environment in plain English to load the Okta-attack chain and generate an actionable engagement plan.