Evilginx Reverse-Proxy AiTM Session Capture Against M365 Login
This rule detects potential Adversary-in-the-Middle (AiTM) phishing attacks targeting Microsoft 365. It monitors for suspicious network connections to known Evilginx-style subdomains (e.g., owa, sso, secure, billing) that proxy traffic to login.microsoftonline.com, followed immediately by a successful user login event on the same host. This pattern indicates an active session hijacking attempt designed to capture session cookies like ESTSAUTH and ESTSAUTHPERSISTENT.
YARA-L

