Detecting Stolen OAuth Tokens: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from April 2022, written in 2026 with the benefit of hindsight.
Stolen OAuth tokens let attackers act as a trusted app without passwords or MFA. Detection focuses on token use that doesn't fit the app's normal behavior.
Signals worth watching
- An integration's token used from IP addresses not belonging to the vendor.
- Bulk repository cloning or data export by an OAuth app.
- OAuth apps accessing resources they rarely touch.
- Sudden activity from dormant integrations.
- Vendor notifications about token compromise.
Where the data lives
- GitHub audit log (organization and enterprise) — includes OAuth app and GitHub App activity,
git.cloneevents with audit log streaming for enterprises. - Microsoft 365: service principal sign-in logs and app governance for OAuth apps connected to Entra ID.
- Salesforce, Google Workspace and other SaaS: connected app and API logs.
- Defender for Cloud Apps for activity across connected SaaS.
A starting approach
Stream your GitHub audit log to Microsoft Sentinel (via the GitHub connector) and alert on:
- Many repository clones by one OAuth application or token in a short period.
- Access to private repositories from IP addresses outside your organization or known CI providers.
For Microsoft 365 apps, monitor service principal sign-ins and app governance alerts for data access spikes.
Response
- Revoke the app's tokens and suspend the integration.
- Identify data accessed (repositories cloned, records exported).
- Search that data for secrets and rotate them.
- Re-enable the integration only after the vendor confirms remediation.