OAuth Token Exfiltration via CLI Tools from Unusual Parent Processes (T1528)
Detects suspicious execution of command-line tools like curl, wget, or PowerShell to query OAuth/token-related endpoints (e.g., /token, oauth, access_token). The rule filters out expected parent processes (e.g., shells, IDEs, common build tools) to identify potentially malicious attempts to steal application access tokens.
SentinelOne

