Malicious OAuth Consent Grant to High-Risk Scopes (T1528)
Detects instances where a user grants OAuth application permissions for high-risk scopes (e.g., mail access, offline access). The rule flags these grants, with higher risk scores assigned if the application publisher is unverified or unknown, helping identify potential illicit consent grant attacks often used to maintain long-term persistence in cloud environments.
YARA-L

