Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies OAuth app consent grants where sensitive permissions (mail, file, directory access) were granted to an unrecognized or anonymous application, which may indicate consent phishing or unauthorized app registration used for data exfiltration.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Hybrid Attack - Cloud & Identity |
| ID | 470f2af8-2b5d-41d4-9be6-686da24f370a |
| Tactics | Collection, Exfiltration, Persistence |
| Techniques | T1528, T1098.001, T1078.004 |
| Required Connectors | AzureActiveDirectory |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
AuditLogs |
OperationName in "Add app role assignment to service principal,Add delegated permission grant,Consent to application" |
✓ | ✗ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity