Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA

PremiumReviewedSigma · High · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-07-09
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Discovery

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects Entra ID sign ins against the Microsoft Authentication Broker application from Node.js based clients such as axios undici and node-fetch as characteristic of Tycoon 2FA adversary in the middle attacks in Elastic research. Automated Node runtimes replaying stolen tokens through the Auth Broker indicate token theft and primary refresh token abuse rather than genuine user interaction.

Related detections9 linkedT1550.001 — drag to rearrange
Suspicious Kubernetes Service Account Token Generation via kubectl
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Suspicious AWS SSO Account Role Enumeration via ListAccountRoles (via cloudtrail)
Malicious TCP Session Hijacking via rshijack
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious Device Registration Following OAuth Token Theft
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious Entra Agent Service Principal Sign-In With PowerShell User Agent via Sign-In Logs
Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
Pivot detection · T1550.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.