Mirage2FA AiTM proxy relay confirmed via correlated spoofed-login/POST/relay chain

Detects Microsoft-branded phishing pages served from non-Microsoft domains, the subsequent credential submission, and the establishment of a WebSocket relay connection characteristic of the Mirage2FA Adversary-in-the-Middle (AiTM) toolkit. This rule correlates multiple stages of the phishing flow to identify active proxy-based credential and MFA bypass attempts.