Detecting OAuth App Abuse: Defender XDR and Sentinel Hunting Queries
OAuth application abuse lets attackers access mailboxes and data with app-level permissions that bypass user MFA. These detections focus on privilege...
Insights
Articles in Detection & Response.
OAuth application abuse lets attackers access mailboxes and data with app-level permissions that bypass user MFA. These detections focus on privilege...
Session tokens taken from HAR files, infostealer logs or phishing proxies are used to access accounts without signing in. Detection focuses on session reuse...
Overly permissive or leaked SAS tokens provide direct access to Azure Storage. These detections help find token exposure and misuse.
Help desk social engineering usually ends with a password or MFA reset followed by an attacker sign-in. These detections connect the two.
Teams chat phishing arrives outside email defenses. These detections help spot suspicious external chats and their consequences.
Forged or stolen tokens let attackers access mailboxes without normal sign-ins. Mailbox access audit events are often the only evidence.
Mass exploitation of file transfer products typically targets web interfaces and ends with bulk data downloads. These detections help catch both stages.
After a CI/CD provider breach, attackers use stolen secrets to access your cloud. Detecting that use — and use of secrets after rotation — tells you whether...
Attackers increasingly target backups — to steal data or to delete it before ransomware. These detections watch for unusual backup access and changes.
Public Azure Blob access is often discovered by outsiders scanning for open containers. Detecting both the configuration and anonymous access helps you find...
MFA push bombing generates bursts of MFA requests. Even with number matching, attackers try variations. These detections help catch attempts early.
Even after patching, exploited Exchange servers may still be compromised. These detections focus on post-exploitation behaviors common to ProxyNotShell and...
SMS phishing campaigns like 0ktapus harvest credentials and MFA codes through fake sign-in pages. Detection focuses on the sign-ins that follow.
AiTM phishing produces a valid session from an attacker's infrastructure. Detection focuses on session anomalies and the business email compromise that...
Malicious Office documents remain a top initial access method. Detecting Office applications launching unusual processes catches many techniques, from...
Stolen OAuth tokens let attackers act as a trusted app without passwords or MFA. Detection focuses on token use that doesn't fit the app's normal behavior.
MFA fatigue attacks generate distinctive patterns: many MFA prompts, many denials, then sometimes an approval. Detecting them early lets you lock down the...
Log4Shell exploitation attempts appear in web logs and network traffic, and successful exploitation often produces outbound connections and unusual processes.
Management agents and VM extensions run with high privilege. Attackers exploit vulnerable agents or abuse extensions to run code. These detections cover both.
Database keys and connection strings, once leaked, are used like legitimate access. Monitoring data plane activity helps you spot misuse.
Remote code execution against Exchange servers leaves traces in IIS logs, process activity and the file system. These detections complement patching.
Low-code apps and portals can expose data without anyone noticing. These detections help surface risky configurations and unusual data access in Power Platform.
MSP supply-chain attacks use legitimate management tools and access. Detection focuses on unusual use of those tools and partner accounts.
Sign-ins without MFA to remote access systems are a leading ransomware entry point. These detections highlight them.