Passkey/SSO phishing domain access (Storm-3121/Storm-3032)
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
Microsoft Sentinel (KQL)

