Invoice/Shared-Doc Phishing Email Leading to Device Code Lure Page
This rule detects potential phishing emails themed around financial documents or shared files that contain URLs associated with device-code authorization phishing lures, such as ARToken PhaaS, or links hosted on workers.dev platforms commonly used for such activities.
Microsoft Sentinel (KQL)

