Quishing-led MFA bypass: QR email followed by risky mobile sign-in

Detects potential Adversary-in-the-Middle (AiTM) MFA bypass attacks (quishing). The rule correlates receipt of an email containing an image attachment (potential QR code) but no URL, followed by a risky mobile sign-in event from a device that is unmanaged or lacks trust within a two-hour window.