{
"AccountObjectId": "11111111-1111-1111-1111-111111111111",
"AccountUpn": "adminuser@example.onmicrosoft.com",
"ActionType": "UnusualAdditionOfCredentialsToAnOauthApp",
"AdditionalFields": {},
"AttackTechniques": [
"Account Manipulation (T1098)",
"Additional Cloud Credentials (T1098.001)"
],
"BehaviorId": "oa315ae74246f1b5d48409bbf90abc388d4f94805893b19e4c77013e797308e9b8",
"Categories": [
"Persistence"
],
"DataSources": [
"Microsoft Cloud App Security"
],
"Description": "The user Admin User (adminuser@example.onmicrosoft.com) performed an unusual addition of credentials to the application dw-activity-gen. This usage pattern may indicate that an attacker has compromised the app, and is using it to spread phishing, exfiltrate data, or to gain access to other accounts and devices. The user added a credential of type AsymmetricX509Cert. A credential of type AsymmetricX509Cert is added when an application is using an application certificate without a key to validate certificate ownership.",
"DetectionSource": "Cloud App Security",
"EndTime": "2026-07-25T20:30:20Z",
"ServiceSource": "Microsoft Cloud App Security",
"StartTime": "2026-07-25T20:08:57Z",
"Timestamp": "2026-07-25T20:41:17.837Z"
}