Steal Application Access Token T1528
Tactic: Credential Access
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Events covered
7 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 17 | PipeEvent (Pipe Created) |
| Sysmon | Event ID 18 | PipeEvent (Pipe Connected) |
| Security-Auditing | Event ID 4663 | An attempt was made to access an object. |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Defender-DeviceEvents | any | Defender event |
| ESF | exec | Process Execution |
Authoring guide
These 80 rules share fields, values, and exclusions.
Fields filtered most (172 distinct)
These fields appear most often in rule filters.
Top indicator values (570 distinct)
These values appear most often in rule predicates.
Exclusions (145 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 16 rules
- Anomalous Token
- Anonymous IP Address
- App Granted Microsoft Permissions
- Application URI Configuration Changes
- Delegated Permissions Granted For All Users
- End User Consent
- End User Consent Blocked
- HackTool - Koh Default Named Pipe
- High Risk Actions - copying of the most powerful token through API Explorer
- High risk event - risk of copying client credentials
- Microsoft Teams Sensitive File Access By Uncommon Applications
- Potentially Suspicious Command Targeting Teams Sensitive Files
- Potentially Suspicious JWT Token Search Via CLI
- Primary Refresh Token Access Attempt
- Renamed BrowserCore.EXE Execution
- Suspicious Teams Application Related ObjectAcess Event
Elastic 31 rules
- Azure AKS Service Account Token Created via TokenRequest API
- Azure Service Principal Sign-In Followed by Arc Cluster Credential Access
- Entra ID AiTM Phishing-Kit Chain Detected
- Entra ID Concurrent Sign-in with Suspicious Properties
- Entra ID Illicit Consent Grant via Registered Application
- Entra ID Kali365 Default User-Agent Detected
- Entra ID OAuth Application Redirect URI Modified
- Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource
- Entra ID OAuth Device Code Flow with Concurrent Sign-ins
- Entra ID OAuth Device Code Sign-in to Azure AD Graph Enumeration
- Entra ID OAuth Flow by Microsoft Authentication Broker to Device Registration Service (DRS)
- Entra ID OAuth Phishing via First-Party Microsoft Application
- Entra ID OAuth PRT Issuance to Non-Managed Device Detected
- Entra ID User Added as Registered Application Owner
- Entra ID User Sign-in with Unusual Client
- GitHub Authentication Token Access via Node.js
- Google Workspace Impossible Travel Login
- Google Workspace Login Flagged Suspicious
- Google Workspace User Login with Unusual ASN
- Kubernetes and Cloud Credential Path Access via Process Arguments
- Kubernetes Service Account Secret Access
- M365 Identity OAuth Flow by First-Party Microsoft App from Multiple IPs
- M365 Identity OAuth Flow by User Sign-in to Device Registration
- M365 Identity OAuth Illicit Consent Grant by Rare Client and User
- M365 Identity Unusual SSO Authentication Errors for User
- Microsoft Entra ID Impossible Travel Sign-in
- Microsoft Graph Request User Impersonation by Unusual Client
- Multi-Cloud CLI Token and Credential Access Commands
- New GitHub Personal Access Token (PAT) Added
- Potential Impersonation Attempt via Kubectl
- Service Account Token or Certificate Access Followed by Kubernetes API Request
Splunk 8 rules
- Azure AD Device Code Authentication
- Azure AD OAuth Application Consent Granted By User
- Azure AD User Consent Blocked for Risky Application
- Azure AD User Consent Denied for OAuth Application
- O365 File Permissioned Application Consent Granted by User
- O365 Mail Permissioned Application Consent Granted by User
- O365 User Consent Blocked for Risky Application
- O365 User Consent Denied for OAuth Application
Kusto 14 rules
- API - JWT validation
- Azure DevOps PAT used with Browser
- Dataverse - Anomalous application user activity
- Detect device token stealing with WDAC
- Expired access credentials being used in Azure
- Identify instances where a single source is observed using multiple user agents (ASIM Web Session)
- Microsoft Entra ID Hybrid Health AD FS Suspicious Application
- Suspicious application consent for offline access
- Suspicious application consent similar to O365 Attack Toolkit
- Suspicious application consent similar to PwnAuth
- Suspicious Entra ID Joined Device Update
- Suspicious Service Principal creation activity
- Trust Monitor Event
- Zero Networks Segment - New API Token created
Panther 11 rules
- AppOmni Alert Passthrough
- Auth0 Refresh Token Reused
- AWS Potentially Stolen Service Role
- Azure VS Code OAuth Phishing
- Kubernetes System Principal Accessed from Non-Cloud Public IP
- Okta AD Agent Authentication Anomaly - Z-Score Detection
- Okta AD Agent Token Abuse - Behavioral
- Okta API Key Created
- Salesforce OAuth Credential Abuse Detection
- Salesforce Third-Party Integration Monitoring
- Zendesk API Token Created