AiTM Session Token Hijacking - Concurrent Session from New IP
Detects potential Adversary-in-the-Middle (AiTM) phishing activity by identifying successful user sign-ins from a new, historically unseen IP address occurring within 30 minutes of a legitimate sign-in from a known IP, indicating the potential replay of a stolen session or refresh token.
Microsoft Sentinel (KQL)

