Malicious OAuth Application Consent Grant (T1550.001)

Detects instances where a user grants OAuth application permissions to an unverified third-party application. The rule specifically monitors for high-privilege scopes such as Mail.Read, Files.ReadWrite.All, or full_access_as_app, which are commonly abused in illicit consent grant attacks to achieve persistent access to sensitive mailbox and cloud data.