Most Popular ShinyHunters 2026 Detection: Anomalous Connected App Scope Escalati
Detects OAuth application consent requests that combine broad API access scopes with persistence-enabling scopes (e.g., offline_access or refresh_token). This pattern is consistent with OAuth consent phishing attacks, where adversaries attempt to gain non-interactive, long-term access to an organization's cloud environment via malicious connected applications.
Sigma

