Category: Security · View source ↗
Security
Session Token Theft Response
Respond to stolen session cookies or tokens after MFA-passed account abuse: revoke sessions and tokens system-wide, not just the user’s password.
Runs as: Skill — you run it in Super Magic and confirm each write; there’s no Flow trigger for this one.
Connectors: Thread — native, no connector required
Role: Security & Compliance Owner, Technician
Outcome: Faster Resolution & Response, Risk & Compliance
When to use: Malicious or anomalous activity on an account where sign-in logs show MFA succeeded and no password change explains it; a user’s session appears active from an unfamiliar IP/device while the user is elsewhere; or post-phishing where the lure harvested a session (adversary-in-the-middle / token-replay), not just credentials.
Run it: on one ticket (a suspected stolen-session case).
Related topics
Your security & compliance runbooksBusiness Email Compromise RecoveryLost or Stolen Device ResponseWas this page helpful?
⌘I