Suspicious M365 Device Code Authentication Flow via m365

PremiumReviewedSigma · Medium · v1
Product
m365
Service
signinlogs
Author
HuntRule
Published
2026-09-28
Updated
2026-09-28

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects Microsoft 365 sign-ins that use the device code authentication flow. The Railway PaaS campaign relied on device code phishing to trick users into authorizing attacker-controlled sessions, so device code grants outside of known kiosk or IoT enrollment scenarios indicate probable phishing-driven token theft.

Related detections9 linkedT1528 — drag to rearrange
Suspicious Entra Device Code Authentication with Office Client and Automated User Agent
Possible Illicit Consent Grant to OAuth Application via Azure AD
Suspicious Device Code Authentication via Microsoft Authentication Broker
Malicious GTFire Phishing Credential Exfiltration to All-in-1.php Backend (via proxy)
Suspicious OAuth Device Code Sign-In to Authentication Broker via Tycoon 2FA
Suspicious OAuth Sign-In Using Visual Studio Code Client and Auth Broker
Suspicious 1Phish Kit Cookies and Telemetry Beacon
Suspicious 1Phish Kit Session API Harvesting Credentials and OTP
Possible AiTM Phishing Sign-On Evaluation Denied by Okta FastPass
Suspicious M365 Device Code Authentication Flow via m365
Pivot detection · T1528 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.