2026 Critical Enterprise Intrusion Chain Detection: AiTM Reverse-Proxy Phishing Domain and Follow-On Sign-In
Detects DNS resolution attempts for newly registered or suspicious top-level domains (e.g., .xyz, .top, .live) that mimic corporate Identity Provider (IdP) or Single Sign-On (SSO) login portals. This behavior is characteristic of Adversary-in-the-Middle (AiTM) phishing kits like EvilProxy or Tycoon2FA, intended to capture user session tokens. Note: This rule monitors for initial domain contact and should be correlated with subsequent authentication logs to identify potential session hijacking.
SentinelOne

