Most Important Detection 2026: Illicit OAuth Consent Grant and Cloud Token Theft
Detects instances where a user grants consent to an unverified OAuth application with high-privilege scopes (e.g., Mail.Read, Directory.Read.All), followed by an authentication event using that same application ID from a different IP address within 24 hours. This behavior is indicative of potential consent phishing or OAuth token abuse, where an adversary harvests tokens to maintain persistent, remote access to email or directory services.
CQL

