Suspicious OfficeHome Sign-In With Axios User Agent via Tycoon 2FA Proxy

PremiumReviewedSigma · High · v1
Product
azure
Service
signinlogs
Author
HuntRule
Published
2026-09-20
Updated
2026-09-20

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. C2

  7. Exfiltration

  8. Impact

What it detects

This rule detects a successful Entra sign-in to the OfficeHome application originating from an axios HTTP client user agent. This pattern is characteristic of the Tycoon 2FA adversary-in-the-middle platform replaying stolen session tokens through automated proxy infrastructure rather than a real browser. A scripted axios agent authenticating interactively indicates session hijacking following a phishing capture.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Suspicious AiTM Session Cookie Exfiltration to log_cookie Endpoint
Suspicious Chrome Launched With Remote Debugging Port For Cookie Theft
Suspicious IAM Persistence and Privilege Escalation Actions
Suspicious AWS STS AssumeRoot Privilege Escalation To Member Account Root
Suspicious AWS Console Phishing MFA Relay Endpoints
Suspicious AWS AiTM Phishing Kit Endpoint Access via Proxy
Suspicious 1Phish Kit Cookies and Telemetry Beacon
Possible AiTM Phishing Sign-On Evaluation Denied by Okta FastPass
Suspicious OfficeHome Sign-In With Axios User Agent via Tycoon 2FA Proxy
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.