Advanced Phishing Tradecraft 2026: Microsoft Device Code Authentication Flow Abu
Detects Azure AD / Entra ID sign-in events that utilize the OAuth 2.0 device code authentication flow. This protocol, designed for input-constrained devices, is frequently exploited by adversary-in-the-middle phishing kits (e.g., EvilTokens) to trick users into authorizing a malicious session, effectively bypassing traditional MFA by obtaining an active session token.
Sigma

