heroui logo

Attachment: ICS with Suspicious Office 365 app authorization (OAuth) link

Sublime Rules

View Source
Summary
This rule detects inbound messages with ICS calendar attachments that contain suspicious Office 365 app authorization (OAuth) links. It targets phishing campaigns where a malicious or compromised app is invited to access a victim’s Office 365 account. The rule inspects ICS files for event links pointing to login.microsoftonline.com and checks for OAuth permission grants in the URL (including offline_access, read, or readwrite scopes) or a reprocess flow indicated by /common/reprocess with ctx and sessionId params. On match, it flags as Credential Phishing with ICS phishing indicators. The detection relies on file analysis of the ICS attachment and URL/content analysis within the ICS events.
Categories
  • Endpoint
  • Web
Data Sources
  • File
Created: 2026-09-28