Top 2026 2FA & AiTM Detection: MFA Approval From Never-Before-Seen Device/ASN Wi
Detects successful multi-factor authentication (MFA) events associated with risk signals categorized as 'unfamiliarFeatures' in Azure AD sign-in logs. This combination is often indicative of an adversary-in-the-middle (AiTM) attack, where the attacker has captured authentication tokens or is forcing an MFA prompt and receiving immediate approval from a new or suspicious device and network location.
Sigma

