CSuite device-code phishing leading to M365 device-code auth
Detects a suspected device-code phishing attack where a user visits a known malicious lure domain and shortly thereafter completes a successful Microsoft 365 device-code authentication. This rule correlates network events with sign-in logs within a 10-minute window to identify session hijacking attempts that bypass traditional MFA.
Microsoft Sentinel (KQL)

