Uncommon Security Info Registration Following AiTM Session Theft (via azure)

PremiumReviewedSigma · Medium · v1
Product
azure
Service
auditlogs
Author
HuntRule
Published
2026-07-22
Updated
2026-08-28

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects a user registering new security info in Entra ID, the persistence step attackers take after adversary-in-the-middle session theft to enroll their own MFA method on a compromised account. Adversaries register a controlled authenticator to retain access after the stolen session expires, making this a useful signal when correlated with anomalous or geo-infeasible sign-ins from the same account.

Related detections3 linkedT1556.006 — drag to rearrange
Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Azure AD Sign-in Success Without MFA (Single-Factor Authentication)
Okta MFA Deactivation or Full Factor Reset Event Detection
Uncommon Security Info Registration Following AiTM Session Theft (via azure)
Pivot detection · T1556.006 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.