OAuth Token Harvesting by Non-Browser Process via T1528
This rule detects processes other than standard web browsers performing network connections that coincide with OAuth token acquisition activities (POST requests containing 'access_token' in the response body). This behavior is indicative of potential token theft or unauthorized programmatic access to OAuth-protected resources.
Splunk (SPL)

