Skip to content

New Query: OAuth2 Token Burst — Token Harvesting (Microsoft Defender for Identity)#56

Merged
dweissbacher merged 1 commit into
mainfrom
submission/d1db3b33-252f-4448-959b-cb130c992e56
May 21, 2026
Merged

New Query: OAuth2 Token Burst — Token Harvesting (Microsoft Defender for Identity)#56
dweissbacher merged 1 commit into
mainfrom
submission/d1db3b33-252f-4448-959b-cb130c992e56

Conversation

@byteray-cql-hub-bot
Copy link
Copy Markdown
Contributor

New Query Submission

Name: OAuth2 Token Burst — Token Harvesting (Microsoft Defender for Identity)
Author: Kundan Kumar
Submission ID: d1db3b33-252f-4448-959b-cb130c992e56

Description

Detects a sudden surge in OAuth2 token requests or acquisitions within a short timeframe, as identified by Microsoft Defender for Identity. This behavior may indicate token harvesting activity, where an attacker attempts to obtain multiple access tokens to abuse authentication sessions and maintain unauthorized access.


This PR was automatically created by the CQL Hub submission pipeline.

@dweissbacher dweissbacher merged commit 5dd6191 into main May 21, 2026
2 checks passed
@dweissbacher dweissbacher deleted the submission/d1db3b33-252f-4448-959b-cb130c992e56 branch May 21, 2026 11:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant