Product
Entra ID Device-Bound PRT Replay via First-Party Apps
1 TTPAdversaries are leveraging stolen Primary Refresh Tokens (PRTs) to perform off-box authentication against Microsoft 365 services by masquerading as first-party FOCI clients from unauthorized IP addresses.
Passkey-Themed Social Engineering Targeting Microsoft Cloud Identities
3 TTPs 10 IOCsThreat actors are using passkey-themed phishing and adversary-in-the-middle attacks to compromise Microsoft cloud accounts, establish persistent access via registered MFA methods, and exfiltrate data via Microsoft Graph API.
Detection of Unusual OAuth Application Access to SharePoint and OneDrive
1 rule 2 TTPsThis brief details a detection strategy for identifying potential OAuth phishing and illicit consent grants by monitoring for first-time application access to Microsoft 365 file storage.
Entra ID Sharepoint or OneDrive Accessed by Unusual Client
2 rules 4 TTPsAn application accessing SharePoint Online or OneDrive for Business for the first time in a tenant could indicate OAuth phishing, illicit consent grants, or compromised third-party apps accessing file storage.