Possible AiTM Session Hijack: MFA-Satisfied Sign-ins from Disparate Locations
Detects potential Adversary-in-the-Middle (AiTM) activity by identifying successful multi-factor authenticated sign-in events from the same user across different geographic regions and IP addresses within a one-hour timeframe, which is characteristic of session cookie replay attacks.
Microsoft Sentinel (KQL)

