2025-03-07 7:24

Happy to announce the release of Microsoft-Analyzer-Suite v1.4.0

It is our first company-branded release! 🚀

The new OAuthPermissions-Analyzer uses the output of the new Graph-based ‘Get-OAuthPermissionsGraph’ cmdlet of the Microsoft-Extractor-Suite v3.0.2, which we co-developed with Invictus Incident Response (Credits to Joey Rentenaar).

We heavily improved the detection of suspicious OAuth Applications (Application Blacklist, Anomalous ReplyUrls, Common Naming Patterns, etc.). Thanks to the valueable new properties and especially for the inspiration by the research of Matt Kiely at Huntress.

Check out the changelog for more information and don’t forget to follow Lethal Forensics on LinkedIn and X. Happy M365 Threat Hunting!