Suspicious OAuth Application Consent / Permission Grant (Entra ID)
Detects OAuth applications receiving permissions to the tenant, used for persistence and data theft. A consented app holds its own token and survives password resets and MFA, which is why consent phishing and post-compromise app registration are favored by both commodity BEC actors and nation-state (PerfectData is linked to Midnight Blizzard / APT29). Tiered: a hardcoded list of known-abused app IDs (PerfectData, eM Client, rclone, Supermailer, and others), layered over a scope-characteristic tier that catches bespoke apps by the permissions they request (Mail/EWS, Files/Sites, Directory, Application, offline_access), with admin/AllPrincipals consent escalating blast radius. Parses all three consent event shapes and resolves app identity across them.
Cortex XDR

