PRT Issuance to Microsoft Graph Shortly After Device Code Auth
Detects the 'GhostCode' attack pattern where an adversary acquires a Primary Refresh Token (PRT) shortly after a successful OAuth device code authentication. This correlation identifies potential session hijacking or token theft resulting from an adversary-controlled device registration.
Microsoft Sentinel (KQL)

