Best Detection of 2026 Series: OAuth Token/Session Cookie Reuse from New ASN Without MFA Challenge

This rule detects successful user logins from multiple geographical locations (impossible travel) where multi-factor authentication (MFA) was not utilized. This behavior is indicative of credential theft or account takeover attempts.