Detecting Suspicious OAuth Application Consent
Overview
Illicit consent grant attacks trick users into granting excessive permissions to malicious OAuth applications in Azure AD / Microsoft Entra ID. This skill uses the Microsoft Graph API to enumerate OAuth2 permission grants, analyze application permissions for overly broad scopes, review directory audit logs for consent events, and flag high-risk applications based on publisher verification status and permission scope.
When to Use
Trigger phrases:
"detecting suspicious oauth application consent"
"Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID u"
When investigating security incidents that require detecting suspicious oauth application consent
When building detection rules or threat hunting queries for this domain
When SOC analysts need structured procedures for this analysis type
When validating security monitoring coverage for related attack techniques
Prerequisites
- Azure AD / Entra ID tenant with Global Reader or Security Reader role
- Microsoft Graph API access with
Application.Read.All, AuditLog.Read.All, Directory.Read.All
- Python 3.9+ with
msal, requests
- App registration with client secret or certificate for authentication
Steps
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Authenticate to Microsoft Graph using MSAL client credentials flow
- Enumerate all OAuth2 permission grants via
/oauth2PermissionGrants
- List service principals and their assigned application permissions
- Query directory audit logs for
Consent to application events
- Flag applications with high-risk scopes (Mail.Read, Files.ReadWrite.All, etc.)
- Check publisher verification status for each application
- Generate risk report with remediation recommendations
Expected Output
- JSON report listing all OAuth apps with granted permissions, risk scores, unverified publishers, and suspicious consent patterns
- Audit trail of consent grant events with user and IP details
When NOT to Use
- You need to perform the attack to test detection (use performing-* skills)
- Task is about analyzing past incidents (use analyzing-* skills)
- You need to implement detection rules (use implementing-* skills)
- Task is about threat hunting proactively (use hunting-* skills)
- You don't have access to logs or monitoring data
- Task requires incident response (use IR skills)
Red Flags
- Performing actions without explicit written authorization from the asset owner
- Testing against production systems without a defined scope and rules of engagement
- Modifying cloud IAM policies or security groups without approval
- Exposing cloud credentials or secrets in logs or reports
- Running scans that generate excessive API calls and trigger billing alerts
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
- All steps executed successfully against a test environment before production use
- Output documented with screenshots or logs demonstrating expected behavior
- Cloud resource changes reverted or documented as intentional
- IAM policies reviewed for least-privilege compliance after testing
- No residual test resources left running (cost and security check)
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: detecting-suspicious-oauth-application-consent3description: Use when detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks. Use when detecting risky oauth application consent grants in azure ad /.4license: Apache-2.05---678# Detecting Suspicious OAuth Application Consent910## Overview1112Illicit consent grant attacks trick users into granting excessive permissions to malicious OAuth applications in Azure AD / Microsoft Entra ID. This skill uses the Microsoft Graph API to enumerate OAuth2 permission grants, analyze application permissions for overly broad scopes, review directory audit logs for consent events, and flag high-risk applications based on publisher verification status and permission scope.131415## When to Use16**Trigger phrases:**17- "detecting suspicious oauth application consent"18- "Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID u"192021- When investigating security incidents that require detecting suspicious oauth application consent22- When building detection rules or threat hunting queries for this domain23- When SOC analysts need structured procedures for this analysis type24- When validating security monitoring coverage for related attack techniques2526## Prerequisites2728- Azure AD / Entra ID tenant with Global Reader or Security Reader role29- Microsoft Graph API access with `Application.Read.All`, `AuditLog.Read.All`, `Directory.Read.All`30- Python 3.9+ with `msal`, `requests`31- App registration with client secret or certificate for authentication3233## Steps3435```python36# Example: IOC detection37import re3839IOC_PATTERNS = {40 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",41 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",42 "hash_md5": r"\b[a-f0-9]{32}\b",43 "hash_sha256": r"\b[a-f0-9]{64}\b",44}4546def extract_iocs(text: str) -> dict:47 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}48```49501. Authenticate to Microsoft Graph using MSAL client credentials flow512. Enumerate all OAuth2 permission grants via `/oauth2PermissionGrants`523. List service principals and their assigned application permissions534. Query directory audit logs for `Consent to application` events545. Flag applications with high-risk scopes (Mail.Read, Files.ReadWrite.All, etc.)556. Check publisher verification status for each application567. Generate risk report with remediation recommendations5758## Expected Output5960- JSON report listing all OAuth apps with granted permissions, risk scores, unverified publishers, and suspicious consent patterns61- Audit trail of consent grant events with user and IP details62## When NOT to Use6364- You need to perform the attack to test detection (use performing-* skills)65- Task is about analyzing past incidents (use analyzing-* skills)66- You need to implement detection rules (use implementing-* skills)67- Task is about threat hunting proactively (use hunting-* skills)68- You don't have access to logs or monitoring data69- Task requires incident response (use IR skills)707172## Red Flags7374- Performing actions without explicit written authorization from the asset owner75- Testing against production systems without a defined scope and rules of engagement76- Modifying cloud IAM policies or security groups without approval77- Exposing cloud credentials or secrets in logs or reports78- Running scans that generate excessive API calls and trigger billing alerts7980## Process81821. **Reconnaissance** — Gather target information, identify attack surface, enumerate services831. **Analysis/Exploitation** — Execute the technique, analyze results, document findings841. **Reporting** — Document IOCs, write findings, provide remediation recommendations8586## Verification8788- All steps executed successfully against a test environment before production use89- Output documented with screenshots or logs demonstrating expected behavior90- Cloud resource changes reverted or documented as intentional91- IAM policies reviewed for least-privilege compliance after testing92- No residual test resources left running (cost and security check)9394## Anti-Rationalization Table9596| Rationalization | Reality |97|---|---|98| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |99| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |100| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |