Most Popular ShinyHunters 2026 Detection: Suspicious OAuth Token Grant from Thir

Detects successful OAuth token grant events for specific third-party SaaS integrations (Salesloft, Drift, Gainsight) where requested scopes include broad permissions such as 'api', 'refresh_token', or 'full'. This pattern is indicative of potential consent phishing or the abuse of a compromised OAuth application to maintain persistent, high-privileged access to SaaS resources.