Sign-in with pre-staged PhoneAppOTP MFA followed by Node.js Graph recon
Detects user account logins following a recent MFA registration (within 1 to 30 days) combined with subsequent network activity that utilizes node.js applications to query the Microsoft Graph API, which may indicate account takeover or malicious persistence setup.
Cortex XDR

