Best Detection of 2026 Series: Adversary-in-the-Middle OAuth and Session Token T
Detects anomalous authentication behavior consistent with Adversary-in-the-Middle (AiTM) phishing attacks, specifically where an MFA-authenticated session is accessed from multiple, disjoint geographic locations or IP addresses within a short timeframe, indicating the replay of stolen session tokens.
YARA-L

