Possible ConsentFix - OAuth Token Theft Detected

Cortex XDR Analytics Alert Reference by data source

Product
Cortex XDR
Last date published
2026-07-12
Category
Analytics Alert Reference
Index by
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

  • Requires:
    • AzureAD

Detection Modules

Identity Threat Module

Detector Tags

ATT&CK Tactic

ATT&CK Technique

Severity

Informational

Description

Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse.
This indicates an attacker has likely bypassed MFA to hijack a user's cloud session.

Attacker's Goals

Bypass identity trust controls to gain persistent unauthorized access to cloud resources.

Investigative actions

  • Check for successful logins to Azure CLI or PowerShell from anomalous IPs.
  • Review sign-in logs for User-Agents associated with CLI tools or scripts.
  • Revoke all active OAuth refresh tokens for the user immediately.

Variations

OAuth Token Theft - Potential Session Hijacking Detected from new ASN

Synopsis

ATT&CK Tactic

ATT&CK Technique

Severity

Low

Description

Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse.
This indicates an attacker has likely bypassed MFA to hijack a user's cloud session.

Attacker's Goals

Bypass identity trust controls to gain persistent unauthorized access to cloud resources.

Investigative actions

  • Check for successful logins to Azure CLI or PowerShell from anomalous IPs.
  • Review sign-in logs for User-Agents associated with CLI tools or scripts.
  • Revoke all active OAuth refresh tokens for the user immediately.