
Summary
This rule detects inbound messages with ICS calendar attachments that contain suspicious Office 365 app authorization (OAuth) links. It targets phishing campaigns where a malicious or compromised app is invited to access a victim’s Office 365 account. The rule inspects ICS files for event links pointing to login.microsoftonline.com and checks for OAuth permission grants in the URL (including offline_access, read, or readwrite scopes) or a reprocess flow indicated by /common/reprocess with ctx and sessionId params. On match, it flags as Credential Phishing with ICS phishing indicators. The detection relies on file analysis of the ICS attachment and URL/content analysis within the ICS events.
Categories
- Endpoint
- Web
Data Sources
- File
Created: 2026-09-28