Skip Navigation
Get a Demo
 
 
 
 
 
 
 
 
 
Resources Videos
Threat intelligence

Red Canary Office Hours: Episode 29 – Uncovering OAuth threats: Detecting malicious Azure phishing campaigns

Air Date: August 19, 2025

Detecting malicious Azure phishing campaigns

Threat Hunters Alex Walston and Harrison Koll from our Intelligence Operations team join Office Hours. They share with us the basics of OAuth, and share the story of a malicious Azure application used to launch phishing campaigns from within the organization.

They then share how we detect these using available signals from Azure audit logs, Microsoft Defender signals, and more.

View the video

Security gaps? We got you.

Sign up for our monthly email newsletter for expert insights on MDR, threat intel, and security ops—straight to your inbox.


 
 
Back to Top