arXiv · 2512.15781
Detecting Malicious Entra OAuth Apps with LLM-Based Permission Risk Scoring
Abstract
This project presents a unified detection framework that constructs a complete corpus of Microsoft Graph permissions, generates consistent LLM-based risk scores, and integrates them into a real-time detection engine to identify malicious OAuth consent activity.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Ashim Mahara. 2025-12-14. Detecting Malicious Entra OAuth Apps with LLM-Based Permission Risk Scoring. https://arxiv.org/abs/2512.15781
Cite the original work for its findings. Save a collection to share your selection of sources.