Overview
This lab provides Sentinel and Defender XDR hunts for device-code phishing, including the 50199-to-success pattern, suspicious client activity, post-token mailbox behavior, and device registration after token issuance.
Start Here
- Read the companion article for the attack model and tuning guidance.
- Open the canonical GitHub repository.
- Follow the README to confirm required log tables, deploy the rules, run the safe replay or telemetry checks, validate results, and clean up lab artifacts.
The included replay data is the preferred starting point; do not conduct phishing against real users.
Verified Implementation Notes
- Sentinel rules use workspace-scoped
Microsoft.SecurityInsights/alertRules@2024-03-01resources. - Synthetic replay rows now use a neutral placeholder app GUID rather than a tenant-created identifier.
- The cleanup helper remains dry-run by default and now validates every supplied client ID, object ID, and display name together before deletion.
- The Microsoft Graph Bicep v1.0 extension requires Bicep 0.36.1 or newer; creating the optional app still changes tenant state and requires app-registration permission.
