Analytics Informational

Possible ConsentFix - OAuth Token Theft Detected

Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006) Execution (TA0002)
ATT&CK techniques: Phishing (T1566) User Execution: Malicious Link (T1204.001) Steal Application Access Token (T1528)
Attacker's goals:

Bypass identity trust controls to gain persistent unauthorized access to cloud resources.

Investigative actions:

Check for successful logins to Azure CLI or PowerShell from anomalous IPs. Review sign-in logs for User-Agents associated with CLI tools or scripts. Revoke all active OAuth refresh tokens for the user immediately.

Test period:
1 Hour
Deduplication:
1 Day
1 variation:
  • OAuth Token Theft - Potential Session Hijacking Detected from new ASN Low (parent: Informational)