OnyxC2 phishing artifact mimicking Microsoft device-code credential add flow
Detects a credential-phishing email linking to a spoofed Microsoft device-code login flow (deviceaddcredential.srf) from a sender/recipient domain mismatch, or delivery of the associated known malicious attachment hash.
Microsoft Sentinel (KQL)

