Mishing Credential Submission: Mobile Geo-Mismatch Auth + MFA Enrollment or Reset T1660 T1078
Detects instances where a user successfully authenticates from a mobile device (Android or iPhone) that exhibits a geographic mismatch (geo_country vs registered_country), and subsequently performs a sensitive credential or MFA-related action (enrollment or reset) from a different device within one hour. This pattern is indicative of a potential session hijacking or credential compromise where an attacker attempts to establish persistence by enrolling their own MFA device.
Splunk (SPL)

