Illicit OAuth App Consent Grant with Sensitive Permissions - T1528

Detects successful OAuth application consent events where the requested permissions include sensitive scopes such as Mail, Files, or User profile access. This is a common indicator of OAuth application-based phishing or persistence attempts, often referred to as 'Illicit Consent Grant' attacks.