Helpdesk MFA/Password Reset Followed by Risky Sign-in (AiTM)
Detects instances where an administrative user performs a password or MFA method reset on a target account, followed within 24 hours by a sign-in event from that same target account flagged with a high or medium risk level. This sequence is characteristic of Adversary-in-the-Middle (AiTM) attacks, where an attacker utilizes stolen session tokens and subsequently coerces helpdesk or administrative intervention to reset MFA requirements to maintain unauthorized access.
Microsoft Sentinel (KQL)

