Phishing Series 2026: Post-Phish MFA Re-Registration & Self-Service Reset Abuse
Detects instances where a user account modifies security information, registers a new MFA method, or resets a password shortly after a successful sign-in from a country not observed for that user within the previous 30 days. This pattern is indicative of potential account takeover where an adversary adds persistence or MFA bypass methods to a newly compromised account.
Microsoft Sentinel (KQL)

