The Detections they give for Sentinel/Defender can be re-written for other SIMs/EDRs. The more interesting item to me is how they paired automation on the backend logic with AI generated phishing lures.
This is a really slick implementation of device code auth. It doesn’t even have the weird context-switching problem of ClickFix, since the DCA is handled entirely in-browser.