Mirage2FA fake CAPTCHA gate followed by spoofed M365 login (non-vendor domain)

Detects a sequence of events where a user interacts with a suspected fraudulent CAPTCHA or slider gate on an non-allowlisted domain, followed by interaction with a spoofed Microsoft 365 login page on the same device within 15 minutes. This behavior is characteristic of the Mirage2FA phishing kit, which intercepts credentials and MFA tokens in real-time.