2026 Critical Enterprise Intrusion Chain Detection: Infostealer Execution Followed by Rapid Cloud Sign-In from New Device
This rule detects a multi-stage attack chain where a device shows signs of credential theft (accessing browser credential stores or cookies) followed closely by a successful cloud authentication from that same user using a device identifier not previously observed in the last 30 days.
Microsoft Sentinel (KQL)

