[Entra ID] Suspicious Continuous OAuth Token Usage

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects repeated use of the same OAuth token across different IPs or locations over time. This can indicate token theft or session abuse.

Attribute Value
Type Analytic Rule
Solution eDCRule
ID 67802748-435b-4f80-9f61-b9a9ac6ea15c
Severity High
Status Available
Kind Scheduled
Tactics CredentialAccess
Techniques T1606
Required Connectors AzureActiveDirectory
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AADNonInteractiveUserSignInLogs
SigninLogs

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to eDCRule