
Summary
Detects inbound messages whose attachments (PDF, HTML, DOCX, PPTX) contain a suspicious Office 365 app authorization (OAuth) link. The attacker may have compromised or provisioned a malicious OAuth app to gain read/write access to the user’s Microsoft 365 account after authorization. The rule targets URLs to login.microsoftonline.com within the attachment and checks for OAuth-related indicators. Specifically, it flags presence of query parameters or path patterns associated with OAuth scopes and persistence mechanisms, including offline_access, read, readwrite, ctx, and prompt=none, or the path /common/reprocess with ctx and sessionId parameters. When matched, it triggers as Credential Phishing using URL analysis. Note: ICS and EML attachments are covered by separate rules. This rule helps detect attempts to authorize malicious apps to access user data via Office 365. The rule references related detections for attachment/ICS/EML variants of the same pattern.
Categories
- Endpoint
- Web
- Identity Management
Data Sources
- File
- Network Traffic
Created: 2026-09-28