Best Detection of 2026 Series – Stolen SSO Session Token Reuse for Cloud Account Takeover
Detects instances where an existing, non-interactive SSO session token is reused from a suspicious network location, such as an anonymizing proxy, VPN, or VPS, or triggered by an impossible travel risk event. The rule specifically looks for token usage that lacks a fresh interactive Multi-Factor Authentication (MFA) challenge, a common indicator of session token hijacking or 'replay' attacks frequently used in cloud account takeover campaigns.
Sigma

