skip to content

Your OAuth consent hunt found only sanctioned grants — what does that disprove, and what does it not?

level: seniorimportance: should knowfreq 44%

answer

  1. the claim was tested, not the estate
  2. scope equals population plus window
  3. absence of a finding is bounded
  4. the kill condition was agreed beforehand
  5. unsanctioned but benign still needs resolving

basics

~20 s

It disproves exactly the claim you wrote: over the grants you queried, in the window you queried, none fell outside the sanctioned set. It says nothing about other persistence routes, other windows, or whether the tenant is clean.

solid answer

~50 s

A falsified hypothesis is a real result, but its scope is the claim, the population and the window — not the estate. I can say that every delegated grant present in the tenant, and every consent recorded in the audit window, resolved to an application we own or contract for with scopes matching its purpose. I cannot say the tenant is uncompromised, that a grant was not created and removed between observations, or that the adversary did not persist by a route I never queried. So the write-up carries the claim, the query, the population, the window and the kill condition that was agreed in advance, and records that the condition was met. The by-products are worth as much as the verdict: a reusable query and a verified inventory of sanctioned applications that the next hunt starts from.

go deeper

for a junior

Remember that finding nothing is a result, and that it only covers what you looked at. Be ready to say exactly what your query included and what it left out.

for a middle

Explain why a clean hunt cannot be reported as 'we are not compromised', and what belongs in the write-up: the claim, the population, the window, the source and the agreed kill condition.

for a senior

Show the discipline of holding to the pre-agreed condition instead of widening a fruitless query, and of resolving an unsanctioned-but-benign grant honestly rather than inflating or burying it.

for a principal

Own how negative results are communicated upward, so a quarter of disproofs reads as measured coverage with stated limits rather than as an assurance the organisation cannot defend.

## The disproof is the deliverable Most hunts end this way, and a hunter who treats a clean result as a failed week will eventually stop writing honest kill conditions. The output of this hunt is a **disproof with a stated scope**, and it is worth writing down properly because the sentence will be repeated by people who were not in the room. A usable write-up contains, in order: the claim as written before querying; where it came from; the population and window queried; the source used; the kill condition agreed in advance; and the result against that condition. Every one of those is load-bearing, because they are what stop the finding being quoted as something larger than it is. ## What you may claim Only the claim. "Every delegated grant present in the tenant and every consent recorded in the window resolved to an application on the sanctioned list, with scopes matching its documented purpose." That is a genuine narrowing of where an adversary can be, and it is defensible against a follow-up question because every term in it maps to something you queried. ## What you may not claim - **That the tenant is clean.** One persistence route was tested. Nothing was tested about the rest. - **That the behaviour never happened.** Anything outside the window is outside the result, and a grant created and removed between your two observations is only visible if the source records removals as well as creations — worth knowing before you write the sentence. - **That the technique cannot happen here.** The hunt measured state, not a control. Nothing about the result says a user could not consent tomorrow. - **That the sanctioned list is correct.** The list was the reference the hunt measured against; the hunt does not validate it. The general form is the one to carry into every hunt: **the absence of a finding is bounded by the population, the window and the source.** State the bounds or someone else will drop them. ## The goalpost failure, in both directions Without a pre-registered kill condition, a clean result pushes the hunter to keep widening — another window, another application population, a looser definition of "unsanctioned" — until something ambiguous appears and gets written up to justify the time. The opposite failure is quieter: an ambiguous result gets waved through as "probably fine" because the hunter wants to close the hunt. Fixing the condition before querying is what makes both of those visible as changes of scope rather than as judgment calls. ## The awkward middle: unsanctioned but benign The common real outcome is one grant to an application nobody sanctioned — a product a team installed for themselves. Under the written condition the hypothesis is **not** killed: the grant is outside the sanctioned set, so it must be resolved. When it resolves to a real employee installing a real product for a real reason, that is a **benign true positive**: the behaviour genuinely occurred, and no adversary is behind it. Record it as such, add the application to the inventory with its owner, and note that the sanctioned list was incomplete when the hunt began. Inflating it into an intrusion and quietly ignoring it are both worse than saying what it was. ## Reporting upward without overclaiming An executive who reads "the hunt found nothing" will repeat "we are not compromised", and the correction is much harder after the fact. Hand the claim over with its bounds attached in the same sentence: we tested one specific persistence route, over a stated set of grants and a stated window, and it was not present; here is what was not tested. Negative results are useful evidence of coverage precisely when they travel with their limits — and useless, or worse, when they do not. ## Closing the hypothesis against the person who raised it If the intel analyst argues the hypothesis should stay open because the report is credible, the answer is that the report's credibility was never what was under test. The claim about the tenant was, the agreed condition was met, and closing it does not say the technique is unlikely — it says you looked, in this population and window, and it was not there. If the analyst wants a different claim tested, that is a new hypothesis with its own kill condition, not this one left running. Whether the check becomes something you repeat is a separate routing decision. What this hunt owes is the honest scope of what it disproved. ## In the interview This is a discipline question, not a technical one. Interviewers are listening for the candidate who says "nothing found" and then, unprompted, states the bounds — population, window, source — and who can describe the unsanctioned-but-benign case without either escalating it or burying it.

  • One grant is to an unsanctioned application a marketing team installed themselves. Does that kill or confirm the hypothesis?
    Neither yet. Under the written condition the hypothesis survives, because the grant sits outside the sanctioned set, so it has to be resolved. When it turns out to be a real employee installing a real product, it is a benign true positive: the behaviour genuinely occurred and no adversary is behind it. Record it, add the application and its owner to the inventory, and note that the sanctioned list was incomplete.
  • An executive reads your report as 'we are not compromised'. How do you correct that?
    Give the claim back with its bounds in the same sentence: we tested one persistence route, over a stated set of grants and a stated window, and it was not present — and here is what was not tested. The correction has to travel with the finding, because a disproof quoted without its scope becomes an assurance nobody in the organisation can support.
  • The intel analyst argues the hypothesis should stay open because the report is credible. How do you close it?
    The report's credibility was never under test; the claim about our tenant was, and the agreed condition was met. Closing it does not say the technique is unlikely, only that we looked in this population and window and it was not there. If the analyst wants a different scope or a different application population examined, that is a new hypothesis with its own kill condition.

A clean result is like a negative test taken on one date for one condition. It describes that day and that condition, not the months around it and not everything else you might have.

saying these in an interview costs you the question

  • Reports a clean hunt as evidence the tenant is not compromised
  • Widens the query after a clean result until something looks odd
  • Treats an unsanctioned but benign grant as an intrusion
  • Writes up the disproof without population, window or source
  • Concludes the technique cannot happen in this environment

context