EvilTokens Phishing Kit - Suspicious Device Code Auth Flow
Detects sign-in events using the device code authentication flow (OAuth 2.0 device authorization grant) where the originating IP address is external to the organization's private network. This flow is often abused by attackers to bypass traditional MFA or interact with headless environments via common HTTP client libraries like Python requests, Go-http, or Axios.
Microsoft Sentinel (KQL)

