Impossible travel via reused refresh token/PRT on non-interactive sign-ins
Detects impossible travel activity for Azure AD accounts by calculating the speed between consecutive sign-in events using the Haversine formula. The rule correlates sign-ins sharing the same SessionId or DeviceId and identifies instances where the calculated travel speed exceeds 900 km/h over a distance greater than 300 km. It includes filtering to exclude known corporate VPN egress points to reduce noise.
Splunk (SPL)

