IT Helpdesk Impersonation: After-Hours Auth Followed by MFA Reset and New Device Registration
Detects a sequence of events within a 30-minute window for a single user, specifically capturing MFA configuration changes (reset/enrollment), authentication, and device registration, occurring outside of typical business hours (20:00 - 06:00). This behavioral pattern is often indicative of an adversary establishing persistence or account takeover after gaining access to a valid account.
Splunk (SPL)

