• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    TrustSink Rogue EAM/OIDC Infrastructure Indicator Hunt

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 13 days ago•1•0•2

    This rule hunts for indicators associated with the TrustSink technique, which involves using rogue External Authentication Methods (EAM) or malicious OIDC providers to bypass authentication or maintain persistence within a cloud environment. It monitors Azure AD sign-in and audit logs, alongside DNS and network events, for references to known malicious domains and URLs used for EAM-based attacks.

    Microsoft Sentinel (KQL)

    Tags

    T1556 - Modify Authentication ProcessT1550.004 - Web Session CookieTA0003 - PersistenceAuthentication AttemptCloud Api CallCloud Identity FederationDNS QueryNetwork Connection OutboundAzureOffice 365Azure Signin LogsM365 Unified Audit Logkql

    Found in

    • TrustSink: Persistent Credential Capture via Rogue MFA ProvidersLast updated 13 days ago
    • TrustSink: Rogue MFA Provider Credential PhishingLast updated 13 days ago
    • TrustSink: Rogue MFA Provider Credential PhishingLast updated 13 days ago
    • TrustSink: Rogue MFA Provider Credential PhishingLast updated 13 days ago
    • TrustSink: Rogue MFA Provider Credential PhishingLast updated 13 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?