AiTM Reverse-Proxy Phishing Domain Serving Rogue Microsoft Login Content
This rule detects access to known adversary-in-the-middle (AiTM) phishing infrastructure mimicking Microsoft login pages. It identifies malicious URLs matching specific randomized path token patterns or those hosting a known phishing domain, while also monitoring for associated session-specific parameters such as 'rt=', 'PHPSESSID', and 'preload=1' cookies, as well as traffic interacting with legitimate 'login.microsoftonline.com' domains in a proxy context.
Microsoft Sentinel (KQL)

