Payroll Pirate AiTM Session Cookie Replay from Proxy IP with Geo Anomaly

Detects potential Microsoft 365 session token replay attacks, often associated with Adversary-in-the-Middle (AiTM) kits. The rule identifies suspicious sign-in activity originating from proxy or anonymized IP addresses where MFA was bypassed or incomplete, coupled with a geographic location that deviates from the user's established 30-day baseline or constitutes a new, unseen location.