EvilTokens Device Code Grant OAuth Token Issuance Followed by Mail Rule BEC

Detects Microsoft 365 OAuth access tokens issued via device_code grant — the mechanism abused by the EvilTokens phishing kit — followed within 1 hour by mailbox forwarding rule creation for the same account, indicating persistent BEC access post-compromise.