Payroll Pirate AiTM: MFA Satisfied on Unmanaged Device with Impossible Travel
This rule detects potential Adversary-in-the-Middle (AiTM) session hijacking by monitoring for successful multi-factor authentication (MFA) events on unmanaged or non-compliant devices, followed within 30 minutes by an API request from a geographically distant location. It includes logic to flag suspicious User-Agent strings often associated with automated AiTM tools.
Microsoft Sentinel (KQL)

