Authentication from EvilToken Infrastructure (Railway.com)
Detects successful user authentications originating from known malicious IP addresses associated with EvilToken infrastructure hosted on Railway.com. This indicates potential compromise via phishing or other credential theft methods.
Microsoft Sentinel (KQL)

