{"id":"9b2cc4c4-2ad4-416d-8e8e-ee6aa6f5035a","title":"End User Consent","description":"Detects when an end user consents to an application","author":"Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow'","status":"test","level":"low","date":"2022-07-28","modified":"","tags":["attack.credential-access","attack.t1528"],"technique_ids":["T1528"],"logsource":{"product":"azure","service":"auditlogs"},"falsepositives":["Unknown"],"references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#end-user-consent"],"source_path":"rules/cloud/azure/audit_logs/azure_app_end_user_consent.yml","source_sha256":"c09f9225d92cf53a3343d00b66ed96f0fba765ad81f434a35340a71e9158265c","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/azure/audit_logs/azure_app_end_user_consent.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: End User Consent\nid: 9b2cc4c4-2ad4-416d-8e8e-ee6aa6f5035a\nstatus: test\ndescription: Detects when an end user consents to an application\nreferences:\n    - https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#end-user-consent\nauthor: Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow'\ndate: 2022-07-28\ntags:\n    - attack.credential-access\n    - attack.t1528\nlogsource:\n    product: azure\n    service: auditlogs\ndetection:\n    selection:\n        ConsentContext.IsAdminConsent: 'false'\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: low\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1528","id":"T1528","name":"Steal Application Access Token","page":"techniques/enterprise/T1528/"}],"data_path":"data/detection-rules/9b2cc4c4-2ad4-416d-8e8e-ee6aa6f5035a.json","kind":"sigma"}
