Top 2026 Detection – Anomalous Device-Code Authentication Volume (Kali365-Style OAuth Token Theft Takeover)

Flags anomalous volume of Entra ID sign-ins using the device-code authorization grant, matching the Kali365 phishing-as-a-service technique (sold on Telegram, ~$250/month per FBI PSA) that captures Microsoft 365 OAuth tokens through the legitimate device-code flow.