Techniques
Sample rules
Applications That Are Using ROPC Authentication Flow
- source: sigma
- technicques:
- t1078
Description
Resource owner password credentials (ROPC) should be avoided if at all possible as this requires the user to expose their current password credentials to the application directly. The application then uses those credentials to authenticate the user against the identity provider.
Detection logic
condition: selection
selection:
properties.message: ROPC