Device Code Authentication Flow Used for Credential Phishing via microsoft.com/devicelogin
This rule detects the use of the OAuth 2.0 Device Code Authorization flow directed towards 'microsoft.com/devicelogin'. This authentication method is frequently abused by attackers in phishing campaigns to hijack device-based user sessions by tricking victims into entering a device code on a malicious site, effectively bypassing traditional password-based authentication.
Sigma

