Steal Application Access Token T1528

Tactic: Credential Access

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

Events covered

7 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 80 rules share fields, values, and exclusions.

Fields filtered most (172 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
data_stream.dataset24eq 22, in 2azure.signinlogs, o365.audit, azure.auditlogs, google_workspace.login, azure.aadgraphactivitylogs
EventType14eq 10, in 4exec, exec_event, executed, login_success, Add registered users to device.
event.outcome12eq 12success
sourcetype8eq 8azure:monitor:aad, o365:management:activity, o365:graph:api
event.type6eq 6start, access, change
OperationName5eq 5, contains 1add delegated permission grant, add oauth2permissiongrant, add service principal, Remove service principal, certificates and secrets management
azure_ad::activity_display_name5eq 5Add app role assignment to service principal, Add service principal, Register device, add owner to application, consent to application
azure_ad::app_id5eq 3, in 229d9ed98-a469-4536-ade2-f981bc1d605e, 00b41c95-dab0-4487-9791-b9d2c32c80f2, 04b07795-8ddb-461a-bbee-02f9e1bf7b46, 0ec893e0-5785-4de6-99da-4ed124e5296c
azure_ad::user_type5eq 5member, Member
event.category5eq 5authentication, process
host.os.type5eq 4, in 1
CommandLine4contains 3, is_not_null 1, regex_match 1 "eyj0ex", "eyjhbg", 'eyj0ex', .*(config-helper\s.*--format|auth\s+print-access-token|au..., /run/secrets/kubernetes.io/serviceaccount
Image4ends_with 3, starts_with 1\microsoft\teams\current\teams.exe, /dev/shm/, /home/, /run/user/, \browsercore.exe
azure_ad::resource_id4eq 4, in 200000002-0000-0000-c000-000000000000, 00000003-0000-0000-c000-000000000000, 01cb2876-7ebd-4aa4-9cc9-d28bd4d359a9
azure_ad::signin_category4eq 4NonInteractiveUserSignInLogs, ServicePrincipalSignInLogs, signinlogs

Top indicator values (570 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
12369
data_stream.dataseteq
azure.signinlogs
1136
data_stream.dataseteq
o365.audit
447
data_stream.dataseteq
azure.auditlogs
326
event.typeeq
start
41078
sourcetypeeq
azure:monitor:aad
447
sourcetypeeq
o365:management:activity
380
Categoryeq
applicationmanagement
313
EventTypein
exec
3201
GrantConsentTypene
AllPrincipals
33
Operationeq
consent to application.
34
OperationNameeq
add delegated permission grant
33
OperationNameeq
add oauth2permissiongrant
33
OperationNameeq
add service principal
33
OperationNameeq
consent to application
35
Workloadeq
azureactivedirectory
330
azure_ad::app_ideq
29d9ed98-a469-4536-ade2-f981bc1d605e
38
azure_ad::logged_by_serviceeq
core directory
311
azure_ad::modified_properties_newcontains
addresstype
33
azure_ad::modified_properties_newgt
0
36
azure_ad::resource_ideq
00000002-0000-0000-c000-000000000000
33
azure_ad::user_typeeq
member
311
displayNameeq
appaddress
35
displayNameeq
consentaction.permissions
35
event.categoryeq
authentication
334
typeeq
serviceprincipal
38
ConsentFullcontains
files.read
22
ConsentFullcontains
files.read.all
22
ConsentFullcontains
mail.read
22
ConsentFullcontains
mail.send
22

Exclusions (145 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imageends_with
\microsoft\teams\current\teams.exe
2
Imageends_with
\browsercore.exe
1
AppIdin
cb1056e2-e479-49de-ae31-7812af012ed8
1
AppIdin
cf6d7e68-f018-4e0a-a7b3-126e053fb88d
1
CommandLinecontains
/bin/test
1
CommandLineeq
/usr/bin/coreutils --coreutils-prog-shebang=cat /usr/bin/cat...
1
CurrentDirectoryeq
/opt/cni/bin
1
CurrentDirectorystarts_with
/home/runner/_work/
1
CurrentDirectorywildcard
/opt/cni/bin
1
CurrentDirectorywildcard
/run/containerd/io.containerd.runtime.v2.task/k8s.io/*/opt/cni/bin
1
EventTypeeq
fork
1
ParentCommandLineeq
runc init
1
ParentCommandLineeq
sh /install-cni.sh
1
ResultTypeeq
0
1
aws::userAgenteq
Windows-AzureAD-Authentication-Provider/1.0
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 16 rules

Elastic 31 rules

Splunk 8 rules

Kusto 14 rules

Panther 11 rules