Top 2026 2FA & AiTM Detection: Redirect Chain to Known AiTM Phishing-as-a-Servic
Detects outbound proxy traffic indicating potential Adversary-in-the-Middle (AiTM) phishing activity. The rule identifies requests directed at domains mimicking major Identity Providers (Microsoft, Okta, Duo, Google) that either utilize punycode homograph encoding or arrive via known URL shortener/redirector services, while filtering out known legitimate brand domains.
Sigma

