Third-party AI connector with broad OAuth scopes read mailboxes and drive at scale
A hard Cybersecurity scenario on Over-Permissioned AI Connector Exfiltration.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 6 templates in this Track + Difficulty pool.
catalog id · ai-connector-overpermissioned-exfil
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Over-permissioned AI-connector containment
- OAuth scope review and least-privilege re-onboarding
- Data from Cloud Storage · CollectionT1530 · TA0009MappedHigh confidence
Trains scoping of a connector reading drives/files at scale.
- Email Collection · CollectionT1114 · TA0009PartialMedium confidence
Trains reasoning about tenant-wide mailbox reads by the connector.
- User Account ContainmentD3-UACMappedHigh confidence
Trains revoking the over-permissioned app grant and its tokens.
- User Account PermissionsD3-UAPMappedHigh confidence
Trains least-privilege re-scoping of the OAuth connector.
- Identity Management, Authentication and Access Control · ProtectPR.AA · PRMappedHigh confidence
Trains consent governance and least-privilege app access.
- Incident Mitigation · RespondRS.MI · RSMappedMedium confidence
Trains revoking grants and tokens to stop ongoing reads.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains bounding what the connector accessed despite partial logs.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains grant/token revocation and least-privilege re-onboarding.
- Vendor/Supplier Cybersecurity Requirements2.RMappedHigh confidence
Trains third-party connector governance and a required DPA.
- Detecting Relevant Threats and TTPs3.AMappedMedium confidence
Trains detection of anomalous high-volume connector reads.
- Service Provider ManagementControl 15MappedHigh confidence
Trains the service-provider control the incident exercises.
- Access Control ManagementControl 6MappedHigh confidence
Trains least-privilege and admin-governed app consent.