Identity & Access ManagementHigh SeverityEstimated SLA: 20 - 40 Minutes

Compromised Credentials, Session Hijacking & Identity Defense

Incident response protocol for compromised employee credentials, infostealer logs, and stolen browser session tokens. Revocation, MFA enforcement, and token flushing.

Triage Progress0 of 6 Steps (0%)

1Phase 1: Immediate Session & Token Revocation

Invalidate All Active SSO Refresh & Access Tokens

Terminating the user's password alone does NOT kill existing OAuth2 refresh tokens or browser session cookies. Force an explicit global session revocation across IdPs.

Revoke-MgUserAllRefreshToken -UserId '[email protected]'

Review Infostealer Dark Web Disclosures

Cross-reference the compromised email with recent Lumma, RedLine, and Vidar stealer dump telemetry to see what browser auto-fill secrets were harvested.

2Phase 2: Device Posture & Phishing-Resistant MFA Enforcement

Isolate Endpoint for Infostealer Malware Removal

If credentials leaked via an infostealer Trojan, changing credentials on the infected workstation will re-leak them instantly. Quarantine the endpoint before resetting credentials.

malwarebytes.exe /scan /quarantine

Enforce Hardware FIDO2 / WebAuthn Authentication

Upgrade the compromised user account to phishing-resistant hardware security keys (YubiKey) or biometric passkeys to render intercepted passwords useless.

3Phase 3: Blast Radius Audit, Forensic Log Review & Hardening

Audit OAuth App Authorizations & Hidden Inbox Forwarding Rules

Verify whether the adversary registered malicious OAuth enterprise applications or created hidden Outlook/Gmail forwarding rules during the intrusion window.

Get-InboxRule -Mailbox [email protected] | Select-Object Name, Description

Revoke Legacy Authentication Protocols Globally

Permanently block legacy protocols (Basic Auth, POP3, IMAP, ActiveSync) across all mailboxes and tenants to eliminate credential replay vectors.

Set-CASMailbox -Identity '[email protected]' -PopEnabled $false -ImapEnabled $false
Share Intel:Share on XLinkedIn

Prepare Your SOC Before the Next Breach

Receive weekly threat briefings, newly published containment playbooks, and mitigation scripts.

Weekly Executive Briefing

Top critical & high-severity threats, every week.

No spam. Unsubscribe anytime. SecOpsPulse may include sponsored security tool recommendations.