Device code auth via Authentication Broker with python-requests UA
Detects anomalous OAuth 2.0 device authorization grant requests where the Microsoft Authentication Broker application ID is utilized by non-standard clients, specifically the python-requests library. This pattern is indicative of the GhostCode phishing backend infrastructure, which attempts to programmatically perform device code phishing rather than relying on interactive browser-based flows.
Microsoft Sentinel (KQL)

