TrustSink Rogue EAM/OIDC Infrastructure Indicator Hunt
This rule hunts for indicators associated with the TrustSink technique, which involves using rogue External Authentication Methods (EAM) or malicious OIDC providers to bypass authentication or maintain persistence within a cloud environment. It monitors Azure AD sign-in and audit logs, alongside DNS and network events, for references to known malicious domains and URLs used for EAM-based attacks.
Microsoft Sentinel (KQL)

