Scenario replay · no production controls connected
GPT-5.6 packets readyEvidence as of 2026-07-18 08:50:00 UTC · 8 cited records · Decision record validatedLocal session
01 · SITUATION
Critical · 88.90SaaS identity compromise2026-07-18 08:50:00 UTC
Finance OAuth compromise
An active Microsoft 365 session is using a malicious OAuth grant with mail, file, and offline-access permissions. An external forwarding rule is present, and the session accessed Finance/Payments files.
Decision to resolveContain the cloud access now, or add endpoint isolation?
Confirmed facts8 cited records
The OAuth app holds delegated mail, file, and offline permissions.C-002 · E-002
A payment-themed external forwarding rule exists in the mailbox.C-004 · E-004
The active session accessed the Finance/Payments library.C-005 · E-003 · E-005
Attack-path topology: External attacker → OAuth consent phishing → Malicious delegated OAuth grant → Active Microsoft 365 session → Finance mailbox → Payment instruction manipulation
Evidence-linked exposure model for Finance OAuth compromise. 10 nodes, 7 directed relationships, and 3 enumerated paths. P-001, Hypothesis path, open. The current endpoint snapshot has no malware detection; this bounded negative finding is shown as non-topological evidence with no causal edge.
External attacker → OAuth consent phishing → Malicious delegated OAuth grant → Active Microsoft 365 session → Finance mailbox → Payment instruction manipulationHypothesis path · modeled reachable
Recommended responseRisk 88.90
THE DECISION
Revoke OAuth sessions and malicious grant
Revoke OAuth sessions and malicious grant ranks first at 96.55/100 because it interrupts 3/3 enumerated paths while accounting for disruption, urgency, reversibility, and evidence strength.
This SVG is drawn from the receipt's real from/to topology. Select a path or preview a response to see exactly which routes close and which remain.
Topology viewExternal attacker → OAuth consent phishing → Malicious delegated OAuth grant → Active Microsoft 365 session → Finance mailbox → Payment instruction manipulation
Base path+ Malware / endpoint
Attack path topology for Finance OAuth compromise. 10 nodes, 7 directed relationships, and 3 enumerated paths. P-001, Hypothesis path, open. The current endpoint snapshot has no malware detection; this bounded negative finding is shown as non-topological evidence with no causal edge.
P-001Hypothesis pathResidual open
External attacker → OAuth consent phishing → Malicious delegated OAuth grant → Active Microsoft 365 session → Finance mailbox → Payment instruction manipulation