{"id":"T1528","name":"Steal Application Access Token","url":"https://attack.mitre.org/techniques/T1528","tactics":["credential-access"],"platforms":["Containers","IaaS","Identity Provider","Office Suite","SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0515","stix_id":"x-mitre-detection-strategy--58bdb4c6-510b-4ffc-9703-852614116ac8","name":"Detection Strategy for T1528 - Steal Application Access Token","url":"https://attack.mitre.org/detectionstrategies/DET0515","analytics":[{"id":"AN1423","stix_id":"x-mitre-analytic--78821450-c84f-498f-abf2-b43211fa4218","name":"Analytic 1423","description":"Access and retrieval of container service account tokens followed by unauthorized API requests using those tokens to interact with the Kubernetes API server or internal services.","url":"https://attack.mitre.org/detectionstrategies/DET0515#AN1423","platforms":["Containers"],"log_source_references":[{"name":"kubernetes:audit","channel":"GET or LIST requests to /var/run/secrets/kubernetes.io/serviceaccount/ followed by access to the Kubernetes API server","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"kubernetes-audit"}],"mutable_elements":[{"field":"TimeWindow","description":"Adjust based on how quickly tokens are expected to be used post-access"},{"field":"UserContext","description":"Tuning for known service accounts that legitimately access the API"}],"live":true,"detection_strategies":["DET0515"],"techniques":["T1528"]},{"id":"AN1424","stix_id":"x-mitre-analytic--70f6482e-e93b-45a5-9b8c-ba7fd0c8220a","name":"Analytic 1424","description":"Token retrieval from instance metadata endpoints such as AWS IMDS or Azure IMDS, followed by API usage using the obtained token from non-standard applications.","url":"https://attack.mitre.org/detectionstrategies/DET0515#AN1424","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"GetInstanceIdentityDocument or IMDSv2 token requests","data_component":"DC0083","data_component_name":"Cloud Service Enumeration","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"Use of temporary credentials issued from IMDS access","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"UserAgent","description":"May need tuning for known automation tools versus unexpected curl usage"},{"field":"TimeWindow","description":"Correlate retrieval and use of token within expected timeout window"}],"live":true,"detection_strategies":["DET0515"],"techniques":["T1528"]},{"id":"AN1425","stix_id":"x-mitre-analytic--a064fdd2-4293-4aff-a91b-e06ac8bf9262","name":"Analytic 1425","description":"Unusual OAuth app registration followed by user-granted OAuth tokens and subsequent high-privilege resource access via those tokens.","url":"https://attack.mitre.org/detectionstrategies/DET0515#AN1425","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:audit","channel":"App registrations or consent grants by abnormal users or at unusual times","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"azure-audit"}],"mutable_elements":[{"field":"ConsentScope","description":"Tunable based on risky or privileged scopes in the environment"},{"field":"AppUserRatio","description":"Threshold of how many users have authorized a given app"}],"live":true,"detection_strategies":["DET0515"],"techniques":["T1528"]},{"id":"AN1426","stix_id":"x-mitre-analytic--da365d5b-c955-46f6-99c2-cd57a3560a57","name":"Analytic 1426","description":"Use of OAuth tokens by third-party apps to access user mail, calendar, or SharePoint resources where the token was granted recently or via spearphishing.","url":"https://attack.mitre.org/detectionstrategies/DET0515#AN1426","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"App-only or delegated access patterns where client_id != known enterprise apps","data_component":"DC0025","data_component_name":"Cloud Storage Access","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"ClientAppIDAllowList","description":"Defenders may allow known app IDs, flag unknowns"},{"field":"AccessVolumeThreshold","description":"Rate of resource access by a newly consented app"}],"live":true,"detection_strategies":["DET0515"],"techniques":["T1528"]},{"id":"AN1427","stix_id":"x-mitre-analytic--0677b819-0586-454c-9f4d-c861ccaf1b73","name":"Analytic 1427","description":"Programmatic access to user content via stolen access tokens in platforms like Slack, GitHub, Google Workspace — especially from new IPs, apps, or excessive resource access.","url":"https://attack.mitre.org/detectionstrategies/DET0515#AN1427","platforms":["SaaS"],"log_source_references":[{"name":"saas:googleworkspace","channel":"Access via OAuth credentials with unusual scopes or from anomalous IPs","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"saas-googleworkspace"},{"name":"saas:slack","channel":"OAuth token use by unknown app client_id accessing private channels or files","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-slack"}],"mutable_elements":[{"field":"GeoVelocity","description":"Flag when token use appears across geographically distant logins"},{"field":"OAuthScopeSensitivity","description":"Weight certain scopes (admin, file.read) as higher risk"}],"live":true,"detection_strategies":["DET0515"],"techniques":["T1528"]}],"live":true,"version":"1.0","techniques":["T1528"]}],"sigma_rules":[{"id":"0055ad1f-be85-4798-83cf-a6da17c993b3","title":"Application URI Configuration Changes","author":"Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik'","status":"test","level":"high","date":"2022-06-02","modified":null,"description":"Detects when a configuration change is made to an applications URI.\nURIs for domain names that no longer exist (dangling URIs), not using HTTPS, wildcards at the end of the domain, URIs that are no unique to that app, or URIs that point to domains you do not control should be investigated.\n","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#application-configuration-changes"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.initial-access","attack.stealth","attack.t1528","attack.t1078.004","attack.persistence","attack.credential-access","attack.privilege-escalation"],"path":"rules/cloud/azure/audit_logs/azure_app_uri_modifications.yml","techniques":["T1528","T1078.004"],"cves":[]},{"id":"0adc67e0-a68f-4ffd-9c43-28905aad5d6a","title":"HackTool - Koh Default Named Pipe","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"critical","date":"2022-07-08","modified":"2023-08-07","description":"Detects creation of default named pipes used by the Koh tool","references":["https://github.com/GhostPack/Koh/blob/0283d9f3f91cf74732ad377821986cfcb088e20a/Clients/BOF/KohClient.c#L12"],"logsource":{"product":"windows","category":"pipe_created"},"tags":["attack.privilege-escalation","attack.credential-access","attack.stealth","attack.t1528","attack.t1134.001"],"path":"rules/windows/pipe_created/pipe_created_hktl_koh_default_pipe.yml","techniques":["T1528","T1134.001"],"cves":[]},{"id":"25cde13e-8e20-4c29-b949-4e795b76f16f","title":"Suspicious Teams Application Related ObjectAcess Event","author":"@SerkinValery","status":"test","level":"high","date":"2022-09-16","modified":null,"description":"Detects an access to authentication tokens and accounts of Microsoft Teams desktop application.","references":["https://www.bleepingcomputer.com/news/security/microsoft-teams-stores-auth-tokens-as-cleartext-in-windows-linux-macs/","https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1528"],"path":"rules/windows/builtin/security/win_security_teams_suspicious_objectaccess.yml","techniques":["T1528"],"cves":[]},{"id":"53acd925-2003-440d-a1f3-71a5253fe237","title":"Anonymous IP Address","author":"Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-08-22","modified":null,"description":"Indicates sign-ins from an anonymous IP address, for example, using an anonymous browser or VPN.","references":["https://learn.microsoft.com/en-us/graph/api/resources/riskdetection?view=graph-rest-1.0","https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#anonymous-ip-address"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.t1528","attack.credential-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_anonymous_ip_address.yml","techniques":["T1528"],"cves":[]},{"id":"6555754e-5e7f-4a67-ad1c-4041c413a007","title":"Anomalous Token","author":"Mark Morowczynski '@markmorow'","status":"test","level":"high","date":"2023-08-07","modified":null,"description":"Indicates that there are abnormal characteristics in the token such as an unusual token lifetime or a token that is played from an unfamiliar location.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#anomalous-token","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.t1528","attack.credential-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_anomalous_token.yml","techniques":["T1528"],"cves":[]},{"id":"65744385-8541-44a6-8630-ffc824d7d4cc","title":"Microsoft Teams Sensitive File Access By Uncommon Applications","author":"@SerkinValery","status":"test","level":"medium","date":"2024-07-22","modified":null,"description":"Detects file access attempts to sensitive Microsoft teams files (leveldb, cookies) by an uncommon process.\n","references":["https://www.bleepingcomputer.com/news/security/microsoft-teams-stores-auth-tokens-as-cleartext-in-windows-linux-macs/","https://www.vectra.ai/blog/undermining-microsoft-teams-security-by-mining-tokens"],"logsource":{"product":"windows","category":"file_access"},"tags":["attack.credential-access","attack.t1528"],"path":"rules/windows/file/file_access/file_access_win_teams_sensitive_files.yml","techniques":["T1528"],"cves":[]},{"id":"6d3a3952-6530-44a3-8554-cf17c116c615","title":"Potentially Suspicious JWT Token Search Via CLI","author":"Nasreddine Bencherchali (Nextron Systems), kagebunsher","status":"test","level":"medium","date":"2022-10-25","modified":"2025-10-21","description":"Detects potentially suspicious search for JWT tokens via CLI by looking for the string \"eyJ0eX\" or \"eyJhbG\".\nJWT tokens are often used for access-tokens across various applications and services like Microsoft 365, Azure, AWS, Google Cloud, and others.\nThreat actors may search for these tokens to steal them for lateral movement or privilege escalation.\n","references":["https://mrd0x.com/stealing-tokens-from-office-applications/","https://www.scip.ch/en/?labs.20240523"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1528","attack.t1552.001"],"path":"rules/windows/process_creation/proc_creation_win_susp_jwt_token_search.yml","techniques":["T1528","T1552.001"],"cves":[]},{"id":"7091372f-623c-4293-bc37-20c32b3492be","title":"End User Consent Blocked","author":"Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow'","status":"test","level":"medium","date":"2022-07-10","modified":null,"description":"Detects when end user consent is blocked due to risk-based consent.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#end-user-stopped-due-to-risk-based-consent"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.credential-access","attack.t1528"],"path":"rules/cloud/azure/audit_logs/azure_app_end_user_consent_blocked.yml","techniques":["T1528"],"cves":[]},{"id":"8a4519e8-e64a-40b6-ae85-ba8ad2177559","title":"Renamed BrowserCore.EXE Execution","author":"Max Altgelt (Nextron Systems)","status":"test","level":"high","date":"2022-06-02","modified":"2023-02-03","description":"Detects process creation with a renamed BrowserCore.exe (used to extract Azure tokens)","references":["https://twitter.com/mariuszbit/status/1531631015139102720"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.stealth","attack.t1528","attack.t1036.003"],"path":"rules/windows/process_creation/proc_creation_win_renamed_browsercore.yml","techniques":["T1528","T1036.003"],"cves":[]},{"id":"9b2cc4c4-2ad4-416d-8e8e-ee6aa6f5035a","title":"End User Consent","author":"Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow'","status":"test","level":"low","date":"2022-07-28","modified":null,"description":"Detects when an end user consents to an application","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#end-user-consent"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.credential-access","attack.t1528"],"path":"rules/cloud/azure/audit_logs/azure_app_end_user_consent.yml","techniques":["T1528"],"cves":[]},{"id":"a6355fbe-f36f-45d8-8efc-ab42465cbc52","title":"Delegated Permissions Granted For All Users","author":"Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow'","status":"test","level":"high","date":"2022-07-28","modified":null,"description":"Detects when highly privileged delegated permissions are granted on behalf of all users","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#application-granted-highly-privileged-permissions"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.credential-access","attack.t1528"],"path":"rules/cloud/azure/audit_logs/azure_app_delegated_permissions_all_users.yml","techniques":["T1528"],"cves":[]},{"id":"a84fc3b1-c9ce-4125-8e74-bdcdb24021f1","title":"Primary Refresh Token Access Attempt","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-07","modified":null,"description":"Indicates access attempt to the PRT resource which can be used to move laterally into an organization or perform credential theft","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#possible-attempt-to-access-primary-refresh-token-prt","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.t1528","attack.credential-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_prt_access.yml","techniques":["T1528"],"cves":[]},{"id":"c1d147ae-a951-48e5-8b41-dcd0170c7213","title":"App Granted Microsoft Permissions","author":"Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow'","status":"test","level":"high","date":"2022-07-10","modified":null,"description":"Detects when an application is granted delegated or app role permissions for Microsoft Graph, Exchange, Sharepoint, or Azure AD","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-applications#application-granted-highly-privileged-permissions"],"logsource":{"product":"azure","service":"auditlogs"},"tags":["attack.credential-access","attack.t1528"],"path":"rules/cloud/azure/audit_logs/azure_app_permissions_msft.yml","techniques":["T1528"],"cves":[]},{"id":"d2eb17db-1d39-41dc-b57f-301f6512fa75","title":"Potentially Suspicious Command Targeting Teams Sensitive Files","author":"@SerkinValery","status":"test","level":"medium","date":"2022-09-16","modified":"2023-12-18","description":"Detects a commandline containing references to the Microsoft Teams database or cookies files from a process other than Teams.\nThe database might contain authentication tokens and other sensitive information about the logged in accounts.\n","references":["https://www.bleepingcomputer.com/news/security/microsoft-teams-stores-auth-tokens-as-cleartext-in-windows-linux-macs/","https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1528"],"path":"rules/windows/process_creation/proc_creation_win_teams_suspicious_command_line_cred_access.yml","techniques":["T1528"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-38475","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}