incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
CybersecuritymediumMalicious OAuth ConsentMedium asset
Scenario

Marketing user clicked Allow on 'Mail Reader Pro' OAuth consent — Mail.ReadWrite + Files.Read.All granted; 47 emails read in 30 min

A medium Cybersecurity scenario on Malicious OAuth Consent.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.

catalog id · oauth-app-consent-mail-reader

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Cloud OAuth consent triage
  • Mailbox-read persistence containment
MITRE ATT&CKmitre-attack
  • Account Manipulation · PersistenceT1098 · TA0003
    MappedHigh confidence

    Trains triage of consent-grant persistence on a cloud account.

MITRE D3FENDmitre-d3fend
  • User Account PermissionsD3-UAP
    MappedHigh confidence

    Trains permission-scoping review on third-party app consent.

  • User Account ContainmentD3-UAC
    MappedMedium confidence

    Trains account containment when consent is suspected to be malicious.

NIST CSF 2.0nist-csf-2
  • Access Control · ProtectPR.AC · PR
    MappedHigh confidence

    Trains access-control posture on cloud OAuth app delegations.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains scoping of consented apps and mailbox-read sessions.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains consent-revocation and audit workflow.

CISA Cybersecurity Performance Goalscisa-cpg
  • Phishing-Resistant MFA2.E
    MappedMedium confidence

    Trains the MFA-resilience baseline against consent attacks.

  • Revoking Credentials for Departing Employees2.D
    PartialLow confidence

    Trains the broader credential-revocation discipline this scenario stresses.

CIS Controls v8cis-controls
  • Access Control ManagementControl 6
    MappedHigh confidence

    Trains the access-control review the scenario centers on.

  • Account ManagementControl 5
    MappedHigh confidence

    Trains the account-lifecycle response on consent-driven access.