Suspicious Entra Sign-In Interrupt With High Aggregated Risk via AiTM DNS Hijacking (via azure)

PremiumReviewedSigma · Medium · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-06-26
Updated
2026-08-28

ATT&CK techniques

Cred Access → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Exfiltration

  11. Impact

What it detects

This rule surfaces Microsoft Entra sign-ins carrying a high aggregated risk score alongside interrupt or success result codes, the pattern seen when SOHO router DNS hijacking redirects victims through an adversary-in-the-middle proxy that replays authentication. Adversaries use the hijacked DNS to intercept credentials and tokens, so high-risk sign-ins clustered with these result codes warrant investigation for token theft and mailbox access.

Related detections9 linkedT1071.004 — drag to rearrange
DoT (DNS Over TLS) Activation - Command (via process_creation)
DoT (DNS Over TLS) Activation - PowerShell (via powershell)
Possible C2 Beacon with Fixed Authorization URI Parameter via proxy
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Malicious TCP Session Hijacking via rshijack
Suspicious FinCounter DNS Tunneling Query via dns_query
Malicious SUNBURST Command and Control DNS Query to avsvmcloud Domain (via dns_query)
Suspicious Exploitation Callback to Dnslog Service (via dns_query)
Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
Suspicious Entra Sign-In Interrupt With High Aggregated Risk via AiTM DNS Hijacking (via azure)
Pivot detection · T1071.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.