APT-level red team operations for enterprises and organizations
CASE FILE RT-0117 SaaS provider

The crown jewels were one consent prompt away

The most efficient operation we ran took no exploit at all: a lure, two approved prompts and one OAuth grant someone accepted months earlier. Customer records left through the front door, sanctioned and logged.

Objective
Exfiltrate a sample of customer records from a multi-tenant SaaS platform
Path
No perimeter exploit was needed. A convincing “new shared inbox policy” lure sent to 40 finance staff yielded two MFA-approved AitM sessions. One account had standing consent to a third-party reporting app with Graph API scope over mailbox data — and the tenant permitted users to approve OAuth grants. Data was staged into a sanctioned-looking SharePoint folder and exfiltrated through an approved sync client.
Detected
The OAuth consent was logged but unmonitored; egress volume from the sync client blended into baseline

After: Tenant-wide OAuth consent restrictions, high-volume egress alerting, and a helpdesk script for verifying “policy” emails.

Names, sectors and infrastructure details are changed; timelines and tradecraft are not. More case files →

The pattern in one page

  • User-approved OAuth grants bypass your perimeter entirely. Restrict consent, inventory standing grants.
  • An approved sync client is the quietest exfiltration channel — it looks exactly like everyone’s daily work.
  • Watch the logs you already generate. The consent event was recorded; nobody was reading it.
Recognize the pattern?
We can verifyTypical effort
The same path against your estate, under signed ROE2–4 wks
Detection validation: what your SOC would have seenincluded
Retest after fixes, within three monthsfree

Could this path exist in your estate?

Tell us your crown jewels — we will tell you how close this case file is to your reality.

Request assessment