2026 Critical Enterprise Intrusion Chain Detection: Impossible Travel Sign-In Using Replayed Session Token
Detects impossible travel sign-in events where a user authenticates from geographically distant locations within a short time window. The rule specifically flags the second, suspicious event as having occurred via a non-interactive session or single-factor authentication, suggesting the use of a replayed or stale session token to bypass MFA.
Microsoft Sentinel (KQL)

