Device Code Sign-in Followed by Rapid Multi-Resource Access
Detects an authentication event using the OAuth 2.0 Device Code grant flow, immediately followed by rapid access to multiple high-value cloud resources. This pattern is characteristic of consent phishing or device code phishing, where an adversary tricks a user into authorizing a malicious application, subsequently using that application's access token to programmatically enumerate or exfiltrate data from various services.
Sigma

