Kali365 / EvilTokens - Device Registration Immediately Post-Device Code Auth
Detects successful Device Code authentication followed immediately by a new device registration, a tactic used to extend access via PRT generation. This behavior is indicative of an attacker using a stolen device code to register a new device, thereby gaining persistent access to the user's account.
Microsoft Sentinel (KQL)

