EvilTokens Device Code Flow OAuth Phishing via Entra ID Sign-in Logs

Detects Microsoft Device Code grant type authentications in Entra ID sign-in logs, consistent with the EvilTokens phishing kit abusing the OAuth device code flow to steal tokens without capturing passwords. Flags DeviceCode protocol sign-ins from browser-based clients, which is atypical for legitimate device code usage.