Category: Security · View source ↗
Security
Session Token Theft Response
Respond to stolen session cookies or tokens after MFA-passed account abuse: revoke sessions and tokens system-wide, not just the user’s password.
Runs as: Skill Run it in Super Magic and confirm each write. A Flow can also fire a shared skill through the Run Skill action (beta), though this one is written for a person to run rather than a ticket event.
Connectors: Thread
Role: Security & Compliance Owner, Technician
Outcome: Faster Resolution & Response, Risk & Compliance
When to use: Malicious or anomalous activity on an account where sign-in logs show MFA succeeded and no password change explains it; a user’s session appears active from an unfamiliar IP/device while the user is elsewhere; or post-phishing where the lure harvested a session (adversary-in-the-middle / token-replay), not just credentials.
Run it: on one ticket (a suspected stolen-session case).
Was this page helpful?