Best Detection of 2026 Series: MFA Push Bombing to Acceptance & Help-Desk Reset Abuse
This rule detects two suspicious patterns related to authentication: (1) 'MFA Fatigue' or 'Push Bombing' where a user experiences a high volume of MFA push denials followed by an acceptance in a short timeframe, and (2) potential account takeover where a help-desk initiated password reset is followed by an MFA re-registration or new device enrollment by the same user within 30 minutes.
Cortex XDR

