Phishing Series 2026: Newly-Consented OAuth App Followed by Mass Mail/File Exfiltration
Detects newly consented OAuth applications that immediately perform mass access or exfiltration of mail and file data across multiple mailboxes or drives within a short period, potentially indicating an attacker utilizing a malicious OAuth application.
Microsoft Sentinel (KQL)

