Top 2026 2FA & AiTM Detection: Certificate/PRT-Based Auth Immediately Following Token Theft Indicator
Detects high-risk sign-in events in Azure AD that exhibit indicators of token replay, impossible travel, or anomalous sessions, while simultaneously leveraging certificate-based authentication or valid Primary Refresh Tokens (PRT). This combination often indicates an adversary is using stolen session material or PRTs to establish persistent, MFA-exempt access to the environment.
Sigma

