OAuth2 Token Endpoint Abuse from Non-Browser Process (ShinyHunters)
Detects network and process execution activity involving Google or Microsoft OAuth2 token endpoints from non-browser and non-trusted processes. This behavior is indicative of potential token theft or session hijacking attempts, where malicious tools (e.g., curl, python) are used to access authentication endpoints to bypass standard user interaction.
SentinelOne

