Payroll Pirate: HR SaaS Direct Deposit Modification After Suspicious Sign-in

Detects instances where a user account modifies sensitive payroll or banking information (e.g., direct deposit details) shortly after performing a sign-in from an unmanaged device or suspicious context. This behavior is indicative of an Adversary-in-the-Middle (AiTM) token replay attack targeting HR SaaS applications like Workday to perform financial fraud.