Skip to content

Commit 1dc7607

Browse files
committed
Update credential_access_azure_entra_susp_device_code_signin.toml
1 parent 0bb317c commit 1dc7607

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

rules/integrations/azure/credential_access_azure_entra_susp_device_code_signin.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,7 @@ references = [
4747
"https://learn.microsoft.com/en-us/entra/identity/monitoring-health/concept-sign-ins",
4848
"https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/reference-azure-monitor-sign-ins-log-schema",
4949
"https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/",
50+
"https://www.wiz.io/blog/recent-oauth-attacks-detection-strategies"
5051
]
5152
risk_score = 73
5253
rule_id = "3db029b3-fbb7-4697-ad07-33cbfd5bd080"

0 commit comments

Comments
 (0)