2026 Critical Cloud Identity Detection: Illicit OAuth Consent Grant to High-Risk Application
Detects OAuth2 permission consent events where a user grants a third-party or newly registered application access to high-risk scopes (such as Mail, Files, or Directory). This technique is commonly used to establish persistence and bypass MFA by gaining access to user accounts via malicious or compromised OAuth applications.
YARA-L

