Skip to main content
Entra ID Device Code Phishing: Token Theft operation cover
IntermediateCloudSIEMEmail

Entra ID Device Code Phishing: Token Theft

A Microsoft 365 user at a financial services firm receives a convincing phishing email asking her to enter a device code at the legitimate Microsoft devicelogin page. The code completes the attacker's OAuth request, handing over a valid token. Working through Entra sign-in logs, Graph audit events, and the email trail, trace how the token was stolen and what the attacker read from the victim's mailbox.

45m
7 tasks
50 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Identify the compromised account

15

One Entra ID account at the financial services firm was accessed through an unusual authentication path overnight. Working through the cloud sign-in and Graph audit trail, identify the user principal that the attacker's token belonged to.

SOC{user@domain}Hint available
2

Name the authentication anomaly

20

Normal corporate users at this organization authenticate through standard flows that include MFA. The attacker exploited a different OAuth grant type that bypassed those controls. Identify the authentication method recorded in the anomalous sign-in event.

SOC{authenticationMethod}Hint available
3

Locate the attacker's first IP

20

The attacker did not use a corporate or trusted address. Trace the earliest malicious activity in the cloud trail and identify the external IP from which the attacker initiated the OAuth token theft and first mailbox access.

SOC{a.b.c.d}Hint available
4

Name the rogue application

20

The attacker registered an application in an external tenant to receive the stolen token. Identify the client ID of that application, as recorded in the Entra audit events.

SOC{xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx}Hint available
5

Identify the phishing sender domain

15

The attack began with a phishing email that impersonated a Microsoft service. The sending domain is not affiliated with Microsoft. Identify the domain that sent the lure email to the victim.

SOC{domain.tld}Hint available
6

Trace what data the attacker accessed

20

Using the stolen token, the attacker called the Microsoft Graph API to access the victim's mailbox. Identify the exact Graph API path that was used to enumerate the inbox contents.

SOC{/v1.0/users/.../mailFolders/inbox/messages}Hint available
7

Classify the credential theft technique

20

The attacker obtained a valid OAuth token for the victim's account without ever knowing the victim's password. Identify the MITRE ATT&CK technique that describes stealing application access tokens through deception of a user.

SOC{Txxxx}Hint available

7 tasks · 130 points total

Training Tools

Cloud Console

Cloud infrastructure logs

SIEM Console

Log analysis & SPL queries

Email Console

Email header & content analysis

Skills You'll Build

Investigate realistic security alerts
Cloud log analysis
SIEM log analysis
Email log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with Cloud concepts
  • Familiarity with SIEM concepts
  • Familiarity with Email concepts

Ready to investigate?

More Operations

View all