Payroll Pirate: HR SaaS Direct Deposit Modification After Suspicious Sign-in
Detects instances where a user account modifies sensitive payroll or banking information (e.g., direct deposit details) shortly after performing a sign-in from an unmanaged device or suspicious context. This behavior is indicative of an Adversary-in-the-Middle (AiTM) token replay attack targeting HR SaaS applications like Workday to perform financial fraud.
Microsoft Sentinel (KQL)

