Evilginx Reverse-Proxy AiTM Session Capture Against M365 Login

This rule detects potential Adversary-in-the-Middle (AiTM) phishing attacks targeting Microsoft 365. It monitors for suspicious network connections to known Evilginx-style subdomains (e.g., owa, sso, secure, billing) that proxy traffic to login.microsoftonline.com, followed immediately by a successful user login event on the same host. This pattern indicates an active session hijacking attempt designed to capture session cookies like ESTSAUTH and ESTSAUTHPERSISTENT.