Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
1 Hour |
Deduplication Period |
1 Day |
Required Data |
|
Detection Modules |
Identity Threat Module |
Detector Tags |
|
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Informational |
Description
Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse.
This indicates an attacker has likely bypassed MFA to hijack a user's cloud session.
Attacker's Goals
Bypass identity trust controls to gain persistent unauthorized access to cloud resources.
Investigative actions
- Check for successful logins to Azure CLI or PowerShell from anomalous IPs.
- Review sign-in logs for User-Agents associated with CLI tools or scripts.
- Revoke all active OAuth refresh tokens for the user immediately.