Rogue OAuth client requesting device code with MS Auth Broker App ID
Detects process creation events containing command-line arguments indicative of an OAuth 2.0 device code flow, commonly used in consent phishing or device code phishing attacks to hijack account access via a malicious OAuth application registration.
SentinelOne

