Tycoon PhaaS: Phishing URL Click with Correlated Risky Sign-In
This rule detects instances where a user clicks on a URL identified as potentially malicious (phishing-related) and subsequently has a risky sign-in event in Azure AD. The rule correlates URL click events from email with Azure AD sign-in logs, specifically looking for sign-ins marked as risky or originating from suspicious user agents (e.g., specific axios versions). The phishing URLs are identified by keywords such as 'azureapplicationregistration.pages.dev', 'chrnobinson.com', 'workers.dev', '.pages.dev', '.web.core.windows.net', '/oauth2/v2.0/authorize', 'client_id=', and 'scope=openid'.
Microsoft Sentinel (KQL)

