Help-Desk Credential Reset Followed by Atypical Sign-In (Vishing Chain)
Detects high-privilege user accounts (e.g., executives, administrators) undergoing a credential or MFA reset, followed by an atypical sign-in event within a two-hour window. This pattern is indicative of potential account takeover or identity-compromise scenarios, often associated with help-desk vishing attacks where an attacker induces a user or administrator to reset credentials or MFA methods.
Microsoft Sentinel (KQL)

