Password spraying
OAuth token abuse and manipulation
Living-off-the-cloud (LotC)
Exploitation of legacy non-production tenants
API-based data exfiltration
Supply chain compromise
Stealthy lateral movement within Microsoft 365 environments
Use of legitimate cloud services for C2