2026 Critical Cloud Identity Detection: Non-Admin User Consent to Multi-Tenant or Unverified Application
Detects mass-phishing consent campaigns by monitoring non-admin users consenting to multi-tenant or unverified-publisher applications requesting non-basic-profile OAuth scopes. The rule aggregates multiple consent events for the same application over a 1-hour window to identify potentially malicious consent-phishing activity.
YARA-L

