Top 2026 2FA & AiTM Detection: OAuth Device Code Flow Phishing Abuse
Detects successful sign-in events using the OAuth 2.0 device authorization grant (device code flow). This technique is frequently abused in AiTM/consent-phishing campaigns where an adversary tricks a user into authorizing a device, effectively obtaining a fully authenticated session token. The rule identifies successful device-code authentications, which should be correlated with source IP discrepancies or unusual volume per tenant to identify malicious activity.
Sigma

