Phishing Series 2026: MFA Push-Bombing / Fatigue Authentication Spam
Detects MFA fatigue or push-bombing attacks where a user account experiences an abnormally high volume of MFA request denials in a short duration (10 minutes), followed by a successful authentication event. The rule specifically looks for evidence where the successful authentication potentially originates from a different IP address than the failed attempts.
Microsoft Sentinel (KQL)

