1. Prerequisites
- OAuth audit logs
- Application consent telemetry
- Identity provider logs
- SaaS integration inventory
- Session telemetry data
- Identity provider access
- OAuth administration portal access
- SIEM platform access
- Cloud audit logs access
- Threat intelligence platform access
2. Step-by-Step Instructions
- Enumerate OAuth Applications
- Identify:
- User-consented applications
- Admin-consented applications
- Third-party integrations
- Newly registered applications
-
Review Granted Permissions
- Assess:
- Mail access permissions
- File access permissions
- Offline access permissions
- Administrative scopes
- API access scopes
- Assess:
-
Identify Suspicious Applications
- Review:
- Unknown publishers
- Recently registered applications
- Excessive permission requests
- Suspicious redirect URIs
- Low-reputation applications
- Review:
-
Review Token Activity
- Identify:
- Long-lived refresh tokens
- Persistent delegated access
- API abuse activity
- Unusual application behaviour
- Identify:
3. Post-Action
- Document all findings within the incident ticket
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Jayden Vo GitHub: https://github.com/jayden-vo
Contributed to the Arcana Incident Response Documentation Framework.
