You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Walkthrough of an authorized cloud red-team CTF I solved: OAuth device-code phishing, token theft, Microsoft Graph and SharePoint enumeration, exfiltration. Plus the KQL hunts and Conditional Access policy that catch it.
Defender-focused analysis of a Microsoft 365 device-code phishing campaign (OAuth device-authorization abuse, MFA-bypassing) - defanged IOCs, Entra hunting, no live samples.