Advanced Phishing Tradecraft 2026: ConsentFix OAuth Application Consent Grant With High-Risk Scopes
This rule detects illicit OAuth consent grant events where an application is granted high-risk delegated permissions. This behavior is indicative of consent phishing or 'ConsentFix' tradecraft, where attackers trick users into granting permissions to a malicious application, thereby enabling unauthorized access to mail and file data.
Sigma

