1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1550.001 Application Access Token — Detection Rules

Detection workspace for T1550.001 Application Access Token: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0185 Behavioral Detection Strategy for Use Alternate Authentication Material: Application Access Token (T1550.001)

AN0526 Analytic 0526

Use of AWS STS or GCP IAM APIs to request temporary tokens or federation sessions inconsistent with normal account activity, including from unexpected principals or regions.

AN0527 Analytic 0527

OAuth or SAML access tokens reused across multiple sessions or clients without corresponding MFA or login activity.

AN0528 Analytic 0528

Application access tokens used to call APIs (e.g., Google Workspace, Salesforce) without interactive logins, often with unusual scopes or elevated permissions.

AN0529 Analytic 0529

OAuth token usage for Exchange Online or SharePoint API access without preceding login or from unauthorized clients.

AN0530 Analytic 0530

Compromised service account tokens mounted inside containers and reused for external API calls or lateral movement across services.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1550.001 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.