Best Detection of 2026 Series: SaaS Supply-Chain Compromise via Malicious Published App/Integration

Detects potential SaaS supply-chain attacks where a third-party application or connector triggers an OAuth permission scope escalation or publishes a new version, followed by the associated service account initiating outbound network connections to rare or newly-registered domains within a 24-hour window.