Analytics
Informational
✕
Possible ConsentFix - OAuth Token Theft Detected
Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006) Execution (TA0002)
ATT&CK techniques: Phishing (T1566) User Execution: Malicious Link (T1204.001) Steal Application Access Token (T1528)
Attacker's goals:
Bypass identity trust controls to gain persistent unauthorized access to cloud resources.
Investigative actions:
Check for successful logins to Azure CLI or PowerShell from anomalous IPs. Review sign-in logs for User-Agents associated with CLI tools or scripts. Revoke all active OAuth refresh tokens for the user immediately.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- OAuth Token Theft - Potential Session Hijacking Detected from new ASN Low (parent: Informational)