OAuth App Consent to High-Privilege Scopes Followed by Mailbox Rule Creation
Detects high-privilege OAuth consent grants to applications shortly followed by suspicious mailbox modifications, such as creating new inbox or transport rules. This behavior is indicative of a post-compromise activity where an adversary uses an illicitly granted OAuth application to maintain persistence or exfiltrate data from an Exchange Online environment.
Microsoft Sentinel (KQL)

