2026 Critical Enterprise Intrusion Chain Detection: OAuth Device Code Phishing a
Detects anomalous OAuth 2.0 device authorization grant sign-in activity within Microsoft 365. The rule identifies suspicious token redemption behavior where the initial device code request and the subsequent token redemption occur from disparate IP addresses or utilize different user-agent strings, which is indicative of EvilTokens or similar adversary-in-the-middle (AiTM) device-code phishing frameworks.
YARA-L

