Fancy Bear OAuth Abuse
This rule detects successful sign-ins using OAuth from residential IP addresses. It joins `SigninLogs` with `IdentityLogonEvents` to correlate successful OAuth authentications with user logon events. The intent is to identify potentially suspicious access, possibly indicating credential abuse or unauthorized access attempts from non-corporate or unexpected locations.
Microsoft Sentinel (KQL)

