Detecting OAUTH Token Theft

Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra ID (Azure AD) token protection, conditional access policies, and sign-in anomaly detection. Covers access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, and pass-the-cookie attacks. Activates for requests involving OAuth token theft detection, token replay prevention, Azure AD conditional access token protection, or cloud identity attack investigation.

luokai0 Updated 10 repo stars

File contents

luokai0/ai-agent-skills-by-luo-kai/tree/main/ai-agent-skills/21-external-registries/08-pinkpixel-collection/detecting-oauth-token-theft commit 5d05db247f

Frequently asked questions

npx skillmds@latest add luokai0/detecting-oauth-token-theft