OnyxC2 phishing artifact mimicking Microsoft device-code credential add flow

Detects a credential-phishing email linking to a spoofed Microsoft device-code login flow (deviceaddcredential.srf) from a sender/recipient domain mismatch, or delivery of the associated known malicious attachment hash.

Microsoft Sentinel (KQL)