Top 2026 2FA & AiTM Detection: MFA Push Bombing / Fatigue Attack
Detects MFA request abuse (T1621) by identifying a user receiving 5 or more MFA push, SMS, or call denials/timeouts within a 10-minute window across Entra ID, Okta, or Duo authentication logs. This behavior is indicative of an MFA fatigue attack, where an adversary continuously triggers MFA prompts until the user eventually approves the request out of frustration or confusion.
Sigma

