Bluekit AitM - MFA OTP Relay via Anomalous Completion Time or IP Mismatch
Detects real-time Multi-Factor Authentication (MFA) OTP relay, commonly associated with Adversary-in-the-Middle (AitM) phishing frameworks like Bluekit. The rule flags successful sign-ins where MFA methods (SMS, TOTP, or Authenticator app) are completed with an abnormally low latency (under 10 seconds), suggesting automated relay, or where discrepancies exist in session context indicative of proxy-based interception.
Microsoft Sentinel (KQL)

