Known Code of Conduct AiTM Campaign Sender Detected
Detects emails originating from sender addresses identified by Microsoft as part of the April 2026 "Code of Conduct" adversary-in-the-middle (AiTM) phishing campaign that targeted Microsoft 365 users and attempted to steal authentication tokens.
Microsoft Sentinel (KQL)

