Most Important ShinyHunters Detection 2026: Suspicious OAuth Consent Grant Impersonating Data Loader

Detects OAuth application consent grant events where an application name matches common 'Data Loader' naming conventions and requests high-privilege scopes (read/write/full/api). This pattern is consistent with consent phishing campaigns used by threat actors to gain persistent access to SaaS environments like M365 or Salesforce.