← LibraryTechnique entry
APT-OKTA-SECredential Access
Identity-Provider Helpdesk SE (Scattered Spider)
Vish the helpdesk for MFA factor reset against an admin user of the IdP (Okta / Entra) — register attacker factor, log in, push policy/factor changes.
§ Where this technique fits
APT-OKTA-SE is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 3 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01Account Manipulationseen 1×T1098 · Persistence