{"id":"T1671","name":"Cloud Application Integration","url":"https://attack.mitre.org/techniques/T1671","tactics":["persistence"],"platforms":["Office Suite","SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0539","stix_id":"x-mitre-detection-strategy--8bc479cf-727b-40d1-92d2-5755766d8544","name":"Detection Strategy for Cloud Application Integration","url":"https://attack.mitre.org/detectionstrategies/DET0539","analytics":[{"id":"AN1487","stix_id":"x-mitre-analytic--6feb9746-7b2c-4f6f-92c9-bfdb14eddddc","name":"Analytic 1487","description":"Detects suspicious OAuth application integrations within Office 365 or Google Workspace environments, such as new app registrations, unexpected consent grants, or privilege assignments. Defenders should correlate between application creation/modification events and associated user or service principal activity to identify persistence via app integrations.","url":"https://attack.mitre.org/detectionstrategies/DET0539#AN1487","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Add app role assignment grant to user: Consent to application by privileged or unexpected accounts","data_component":"DC0066","data_component_name":"Active Directory Object Modification","log_source_slug":"m365-unified"},{"name":"azure:audit","channel":"Consent to application: OAuth application consent granted to service principal","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"azure-audit"}],"mutable_elements":[{"field":"PrivilegedUserList","description":"Defines which accounts are authorized to consent or register applications; deviations indicate possible adversary persistence."},{"field":"ApplicationScopeThreshold","description":"Defines which OAuth scopes are considered risky (e.g., Mail.ReadWrite, Files.ReadWrite.All)."}],"live":true,"detection_strategies":["DET0539"],"techniques":["T1671"]},{"id":"AN1488","stix_id":"x-mitre-analytic--036a6a5d-bd87-45c7-bd68-43df76167786","name":"Analytic 1488","description":"Detects anomalous SaaS application integration activity across environments such as Slack, Salesforce, or other enterprise SaaS services. Focus is on unauthorized app additions, unusual permission grants, and persistence through service principal tokens.","url":"https://attack.mitre.org/detectionstrategies/DET0539#AN1488","platforms":["SaaS"],"log_source_references":[{"name":"saas:integration","channel":"New or modified third-party application integrations with elevated permissions","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"saas-integration"},{"name":"saas:audit","channel":"Application added or consent granted: Integration persisting after original user disabled","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-audit"}],"mutable_elements":[{"field":"AppWhitelist","description":"Defines approved SaaS integrations for the enterprise; deviations indicate suspicious persistence."},{"field":"ConsentDelegationPolicy","description":"Threshold for which users can self-consent integrations; lowering this may reduce false positives."}],"live":true,"detection_strategies":["DET0539"],"techniques":["T1671"]}],"live":true,"version":"1.0","techniques":["T1671"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}