AiTM/Device-Code Auth Flow Bypassing MFA

This rule detects successful user authentication events within the environment. It acts as a base filter to capture login success, which can be further refined with context such as IP addresses or usernames to monitor for anomalous login patterns, though it does not inherently provide detection of complex attacks like session token hijacking on its own.