EvilTokens Post-OAuth OneDrive Redirect After Device Code Phishing
Detects a browser session that contacts an EvilTokens Device Code phishing endpoint (/api/device/status/) and then immediately navigates to onedrive.live.com. This indicates that the attacker's backend successfully returned 'status:completed' and the phishing kit executed a window.location.replace to redirect the victim to OneDrive after token capture.
Microsoft Sentinel (KQL)

