THREAT-001Cloud access after device-code phishing
Attackers initiated legitimate device-code requests, persuaded targets to authorize them, and used the resulting cloud access for follow-on activity.
How it began: Target authorizes a device-code request
Behavior to watch: A successful device-code sign-in occurs outside the account's documented application or device workflow.