Token Refresh from New IP After MFA Sign-In - Possible Session Hijack (T1528/T1550.001)

This rule detects potential token theft or MFA bypass by correlating successful MFA-satisfied interactive sign-ins with subsequent non-interactive sign-ins (token refreshes) occurring within a 60-minute window from different IP addresses for the same user. This pattern is indicative of an attacker stealing a session token (e.g., via session cookie theft or AiTM phishing) and using it to authenticate from a different location.