OAuth consent grant of high-risk scopes (offline_access, Mail/Files) after sign-
Detects instances where a user grants high-privilege permissions (Mail.Read, Files.ReadWrite.All, offline_access) to an OAuth application within 24 hours of a risky sign-in event. This pattern is commonly observed in AiTM (Adversary-in-the-Middle) or consent-phishing attacks designed to establish persistent access to cloud resources.
Microsoft Sentinel (KQL)

