Multi-CloudDetection & ResponseRetrospectives

Detecting Stolen OAuth Tokens: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2022, written in 2026 with the benefit of hindsight.

Stolen OAuth tokens let attackers act as a trusted app without passwords or MFA. Detection focuses on token use that doesn't fit the app's normal behavior.

Signals worth watching

  • An integration's token used from IP addresses not belonging to the vendor.
  • Bulk repository cloning or data export by an OAuth app.
  • OAuth apps accessing resources they rarely touch.
  • Sudden activity from dormant integrations.
  • Vendor notifications about token compromise.

Where the data lives

  • GitHub audit log (organization and enterprise) — includes OAuth app and GitHub App activity, git.clone events with audit log streaming for enterprises.
  • Microsoft 365: service principal sign-in logs and app governance for OAuth apps connected to Entra ID.
  • Salesforce, Google Workspace and other SaaS: connected app and API logs.
  • Defender for Cloud Apps for activity across connected SaaS.

A starting approach

Stream your GitHub audit log to Microsoft Sentinel (via the GitHub connector) and alert on:

  • Many repository clones by one OAuth application or token in a short period.
  • Access to private repositories from IP addresses outside your organization or known CI providers.

For Microsoft 365 apps, monitor service principal sign-ins and app governance alerts for data access spikes.

Response

  1. Revoke the app's tokens and suspend the integration.
  2. Identify data accessed (repositories cloned, records exported).
  3. Search that data for secrets and rotate them.
  4. Re-enable the integration only after the vendor confirms remediation.
detect stolen oauth tokensHeroku/Travis CI OAuth2022

More on this story