LoFP LoFP / this detection is low-volume and is seen infrequently in most organizations. when this detection appears it's high risk, and users should be remediated.


Sample rules

Primary Refresh Token Access Attempt


Indicates access attempt to the PRT resource which can be used to move laterally into an organization or perform credential theft

Detection logic

condition: selection
  riskEventType: attemptedPrtAccess