Top 2026 2FA & AiTM Detection: Session/Refresh Token Reuse Across Divergent Device Fingerprints

Detects the reuse of session identifiers (SessionId, DeviceId, or RefreshTokenJti) across different device fingerprints (e.g., changes in User-Agent, OS, or Browser) within a short timeframe. This behavior is indicative of session hijacking or adversary-in-the-middle (AiTM) attacks, where stolen session tokens or cookies are replayed by an attacker from a different endpoint than the original user.