Anomalous OAuth scope, redirect_uri, or client_id in auth flow

This rule monitors audit logs for anomalous OAuth application configurations, specifically focusing on excessive scope counts, Redirect URI mismatches, Client ID mismatches, and cross-client token exchange irregularities, which may indicate malicious OAuth application registration or configuration for token theft.