3 OAuth TTPs Seen This Month — and How to Detect Them with Entra ID Logs
ID: fe1b1dc5-67e4-5cf7-b994-30dc55411dad
STIX ID: report--fe1b1dc5-67e4-5cf7-b994-30dc55411dad
Feed Name: Wiz Blog
This report examines how attackers exploit OAuth mechanisms in Azure Entra ID—specifically the device code flow and ROPC—to obtain access tokens, bypass MFA, and establish durable persistence through device registration and Windows Hello for Business. It outlines observable patterns in sign-in telemetry, highlights prevalent misconfigurations in Conditional Access, and supplies ready-to-use KQL queries to detect device-code phishing, ROPC-based brute force and MFA bypass, and suspicious device/WHfB registrations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
