Product
Passkey-Themed Social Engineering Targeting Microsoft Cloud Identities
3 TTPs 10 IOCsThreat actors are using passkey-themed phishing and adversary-in-the-middle attacks to compromise Microsoft cloud accounts, establish persistent access via registered MFA methods, and exfiltrate data via Microsoft Graph API.
Detection of Unusual OAuth Application Access to SharePoint and OneDrive
1 rule 2 TTPsThis brief details a detection strategy for identifying potential OAuth phishing and illicit consent grants by monitoring for first-time application access to Microsoft 365 file storage.
Microsoft 365 OAuth Device Code Phishing Exploits Non-Compliant Devices
2 rules 3 TTPsAttackers are actively exploiting the OAuth device code flow in Microsoft 365 to bypass multi-factor authentication (MFA) and gain initial access, leveraging phishing kits like Kali365 and tradecraft similar to Storm-2372 to harvest MFA-satisfied tokens from non-compliant or attacker-controlled devices, and subsequently establishing persistence through device registration.
O365 Security Compliance Alerting for Potential Ransomware Activity
3 rules 3 TTPsThis brief focuses on detecting potential ransomware activity within Microsoft Office 365 environments by monitoring security and compliance alerts, aiding in early identification and mitigation of ransomware threats.
Entra ID Sharepoint or OneDrive Accessed by Unusual Client
2 rules 4 TTPsAn application accessing SharePoint Online or OneDrive for Business for the first time in a tenant could indicate OAuth phishing, illicit consent grants, or compromised third-party apps accessing file storage.