Detecting SaaS OAuth Token Theft: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from August 2025, written in 2026 with the benefit of hindsight.
Stolen OAuth tokens used for data theft show up as bulk API activity from integrations. These detections help catch it.
Signals worth watching
- An integration's API calls from IP addresses outside the vendor's known ranges.
- Bulk queries or exports (for example, large Salesforce SOQL queries on Account, Contact, Case, User objects).
- Queries searching for strings like "AKIA," "password," "secret" or "token."
- Deletion of query jobs or export records after execution.
- Spikes in API usage by a connected app.
- Vendor or platform notices about revoked tokens.
Where the data lives
- Salesforce Event Monitoring (API events, report exports, login history) — some events require Shield or Event Monitoring licenses.
- Microsoft 365: service principal sign-in logs, audit logs, app governance.
- Google Workspace token and API audit logs.
- Defender for Cloud Apps for connected SaaS.
A starting approach
- Baseline each integration's normal API volume and source IPs.
- Alert when volume exceeds the baseline by a large factor or when calls come from new IP ranges.
- For Microsoft 365, monitor service principal sign-ins:
AADServicePrincipalSignInLogs
| where ResultType == "0"
| summarize Calls = count(), IPs = make_set(IPAddress, 20) by ServicePrincipalName, bin(TimeGenerated, 1h)
Response
- Revoke the integration's tokens and disable the connected app.
- Determine data accessed and exported.
- Search exported data for secrets and rotate them.
- Notify affected parties as required.
- Salesloft Drift (Aug 2025): Stolen OAuth Tokens Hit Hundreds of Salesforce Tenants Incident Teardowns
- How to Audit SaaS-to-SaaS OAuth Integrations and Token Scopes How-To & Hardening
- CIO Brief: Every Integration Is a Trust Relationship CIO Briefings