huntresslabs / rogueapps

When good OAuth apps go rogue. Documents observed OAuth application tradecraft
https://huntresslabs.github.io/rogueapps/
Mozilla Public License 2.0
42 stars 7 forks source link

Transfer this across #17

Open randomaccess3 opened 2 months ago

randomaccess3 commented 2 months ago

https://github.com/randomaccess3/detections/blob/main/M365_Oauth_Apps/MaliciousOauthAppDetections.json

Happy for someone to port my json file across, this site looks much nicer. Creating the issue so I remember when I have time, but if someone else wants to migrate it then please do.

syne0 commented 2 months ago

I was considering starting to move these over as well! I use the json file you linked in my Osprey tool so I'd just have to change that code. It's just a little lighter on some of the app sources/references than I'd like, so I'm working on more research and building documentation about those rarer apps.

HuskyHacks commented 2 months ago

Hey @randomaccess3 and @syne0,

Thank you both for your contributions so far!

@randomaccess3 I've already included your repo as a reference in one RogueApp entry and I know you have a bunch of other apps listed in that same detection repo, so I can go ahead and add you as a contributor for any app that uses your repo as a reference. Does that work for you?

randomaccess3 commented 2 months ago

Yep no problem.

HuskyHacks commented 2 months ago

@randomaccess3 I added you to the contributors for PerfectData Software in https://github.com/huntresslabs/rogueapps/commit/a17db70612b9852e5545a5d2848ff1f8e9d55f1e