T1528 Steal Application Access Token
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used as a way to access resources in cloud and container-based applications and software-as-a-service (SaaS).(Citation: Auth0 - Why You Should Always Use…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- HackTool - Koh Default Named Pipecriticaltest · windows
- Anomalous Tokenhightest · azure
- Anonymous IP Addresshightest · azure
- App Granted Microsoft Permissionshightest · azure
- Application URI Configuration Changeshightest · azure
- Delegated Permissions Granted For All Usershightest · azure
- Primary Refresh Token Access Attempthightest · azure
- Renamed BrowserCore.EXE Executionhightest · windows
- Suspicious Teams Application Related ObjectAcess Eventhightest · windows
- End User Consent Blockedmediumtest · azure
- Microsoft Teams Sensitive File Access By Uncommon Applicationsmediumtest · windows
- Potentially Suspicious Command Targeting Teams Sensitive Filesmediumtest · windows
- Potentially Suspicious JWT Token Search Via CLImediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.