Stolen M365 Session Token Replay via Non-Interactive OAuth2:Token Graph Request
Detects anomalous non-interactive OAuth token requests against Microsoft Graph that claim multi-factor authentication (MFA) satisfaction from unmanaged devices. This behavior is indicative of Adversary-in-the-Middle (AiTM) token replay attacks, where captured session tokens are reused by an attacker to bypass authentication controls, consistent with tactics used by threat actors like Storm-2755 (Payroll Pirate).
Cortex XDR

