Suspicious Entra Sign-In to OfficeHome with axios User Agent

PremiumReviewedSigma · High · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-06-28
Updated
2026-08-28

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. C2

  7. Exfiltration

  8. Impact

What it detects

This rule detects a successful Entra ID sign-in to the OfficeHome application where the user agent contains axios, an automation library used by the Tycoon 2FA adversary-in-the-middle platform. Tycoon 2FA relayed intercepted credentials and stolen session cookies through scripted axios clients to authenticate as the victim. A non-browser axios agent completing sign-in to OfficeHome indicates automated session token replay from an AiTM phishing kit.

Related detections9 linkedT1078.004 — drag to rearrange
Possible Citrix Bleed Session Token Leak via OpenID Configuration Endpoint (CVE-2023-4966) (via webserver)
Uncommon Browser Launched with Remote Debugging Port for Cookie Theft (via process_creation)
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious Sneaky 2FA Phishing Kit License Check via API Key Endpoint (via proxy)
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Malicious TCP Session Hijacking via rshijack
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.