Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365

PremiumReviewedSigma · Medium · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-08-20
Updated
2026-08-28

ATT&CK techniques

Initial Access → C2
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. Exfiltration

  8. Impact

What it detects

This rule detects Microsoft 365 sign-in events blocked by Conditional Access after a valid password was supplied, which can indicate credential stuffing or password spraying against accounts protected only by MFA. Huntress observed adversaries validating stolen credentials from VPN, Tor, and proxy sources before attempting session takeover. A spike of these blocks from anomalous geographies surfaces pre-MFA account compromise that would otherwise be silent.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious Flax Typhoon System Utility Masquerade Outside System32 via Renamed VPN Client (via process_creation)
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
Possible ReverseSocks5 Tunneling Tool Execution on Linux (via process_creation)
Suspicious AWS Console Login Without MFA
Suspicious Cloud Sign-In From an Anonymizer or High-Risk Session (via signinlogs)
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.