Phishing Series 2026: Phishing Kits Hosted on Trusted Cloud Infrastructure (Azure/Cloudflare/Firebase)
Detects phishing emails containing suspicious URLs pointing to PaaS platforms (Azure Static Web Apps, Cloudflare, Firebase) that exhibit credential harvesting characteristics (branded keywords or base64 patterns). The rule correlates these emails with subsequent clicks and a successful M365 sign-in by the same user within 30 minutes of the click, indicating a probable successful credential compromise.
Microsoft Sentinel (KQL)

