Best Detection of 2026 Series: Adversary-in-the-Middle OAuth and Session Token T

Detects anomalous authentication behavior consistent with Adversary-in-the-Middle (AiTM) phishing attacks, specifically where an MFA-authenticated session is accessed from multiple, disjoint geographic locations or IP addresses within a short timeframe, indicating the replay of stolen session tokens.