Suspicious M365 Sign-In from Programmatic Password Spraying User Agent

PremiumReviewedSigma · Medium · v1
Product
m365
Service
signinlogs
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects Microsoft 365 sign-in activity presenting user agents associated with programmatic HTTP libraries and password spraying frameworks such as Axios, python-requests, CredMaster, and TREVORspray. These clients drive automated credential attacks against cloud identities from non-interactive infrastructure. Programmatic sign-in agents against user accounts indicate credential stuffing or spraying rather than legitimate browser access.

Related detections6 linkedT1110.003 — drag to rearrange
Suspicious Entra ID Password Spraying via ROPC Grant to Azure CLI App
Suspicious Entra ROPC Password Spray Against Azure CLI Client
Suspicious Go HTTP Client User Agent via Proxy
Suspicious macOS Local Credential Validation via dscl authonly
Suspicious Bruteforce via Password Reset (via security)
Suspicious Peach Sandstorm Password Spray via go-http-client User Agent (via proxy)
Suspicious M365 Sign-In from Programmatic Password Spraying User Agent
Pivot detection · T1110.003 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.