Skip to main content
Category: Security · View source ↗
Connectors: none — works with Thread out of the box Role: Security & Compliance Owner, Technician Outcome: Risk & Compliance, Faster Resolution & Response When to use: An alert fires for a newly consented enterprise app, a risky OAuth grant, or an unfamiliar app with mail/file permissions; a user reports approving an app “to view a document” that then behaved oddly; or persistence hunting during a takeover/BEC recovery surfaces an attacker-added app consent. Run it: on one ticket (a suspicious OAuth grant).

Prompt