Suspicious Entra Device Code Authentication with Office Client and Automated User Agent

PremiumReviewedSigma · High · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-05-18
Updated
2026-08-28

ATT&CK techniques

Initial Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Discovery

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects Entra ID sign-ins using the device code authentication flow against the Microsoft Office client application from an automated python-requests user agent, matching the Kali365 device code phishing ecosystem. Adversaries phish device codes to obtain refresh tokens for the well-known Office client and replay them programmatically to access mailboxes. Device code flow paired with a scripted user agent is a strong indicator of token theft and mailbox compromise.

Related detections9 linkedT1550.001 — drag to rearrange
Malicious PRT Token Forging via AADInternals (via ps_script)
Suspicious AWS SSO Token Creation and Role Credential Retrieval (via cloudtrail)
Malicious OAuth Application Granted Full Mailbox and EWS Permissions (via m365)
Suspicious Kubernetes Service Account Token Generation via kubectl
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
Suspicious GAM OAuth Token Enumeration via Process Creation
Suspicious AWS SSO Account Role Enumeration via ListAccountRoles (via cloudtrail)
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious Device Registration Following OAuth Token Theft
Suspicious Entra Device Code Authentication with Office Client and Automated User Agent
Pivot detection · T1550.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.