Possible Illicit Consent Grant to OAuth Application via Azure AD

PremiumReviewedSigma · Low · v1
Product
azure
Service
auditlogs
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Discovery

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects a user or admin consent grant to an OAuth service principal, a technique used in the illicit consent grant attacks documented by Huntress. Adversaries lure victims into consenting to attacker-controlled applications to obtain long-lived access tokens for mail and directory data. Because legitimate app consent is common, this detection is best paired with anomalous application naming or reply URLs and treated as a hunting lead.

Related detections9 linkedT1528 — drag to rearrange
Malicious PRT Token Forging via AADInternals (via ps_script)
Suspicious Entra Device Code Authentication with Office Client and Automated User Agent
Suspicious AWS SSO Token Creation and Role Credential Retrieval (via cloudtrail)
Suspicious Device Code Authentication via Microsoft Authentication Broker
Suspicious OAuth Device Code Sign-In to Authentication Broker via Tycoon 2FA
Suspicious Google Workspace OAuthLogin From Node.js Client via Tycoon 2FA
Suspicious OAuth Sign-In Using Visual Studio Code Client and Auth Broker
Malicious GCP Service Account Backdoor via serviceAccountTokenCreator Grant
Suspicious GCP Service Account Impersonation via GenerateAccessToken
Possible Illicit Consent Grant to OAuth Application via Azure AD
Pivot detection · T1528 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.