BigHugger
sk Skill · mukul975

detecting-oauth-token-theft

Detect and respond to OAuth token theft and replay in Microsoft Entra ID (Azure AD), covering access token theft, refresh token replay, Primary Refresh Token (PRT) abuse, pass-the-cookie attacks, and Token Protection conditional access policies. Use for impossible-travel or anomalous token-usage alerts, suspected session hijacking, sign-in log analysis, or configuring token-binding defenses in Azure/M365.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
PythonPRTidentity-securitytoken-replayconditional-accessentra-idkustoazure-adpowershelltoken-theftoauth
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0.0
Licence
Apache-2.0
Host stars
33k
Host language
Python