Here's a Worker running a threat hunt for OAuth app-consent abuse across Entra, JumpCloud, and AWS.
Result?
Thirty-five minutes. Structured hypothesis, 25 queries across three platforms, five detections ready for soak, and a gap inventory that makes the next hunt better.