Microsoft 365Detection & ResponseNews

Detecting MFA Bypass Phishing Kit: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Token theft through phishing kits produces sessions that look legitimate but come from attacker infrastructure. These detections help find them.

Signals worth watching

  • Entra ID Protection detections: Anomalous token, Attacker in the middle, Unfamiliar sign-in properties, Token issuer anomaly.
  • Sessions used from an IP or ASN different from where they started, especially hosting providers.
  • Device code sign-ins outside approved accounts.
  • Non-compliant or unregistered devices accessing mail after a sign-in from a compliant device.
  • Mailbox activity — inbox rules, mass reads, external forwarding — shortly after a new session.

Where the data lives

  • Entra ID sign-in logs (interactive and non-interactive) and Identity Protection.
  • Unified audit log and Defender XDR (CloudAppEvents).
  • Defender for Office 365 URL click data, to find the phishing message.

A starting query

Risky sign-ins followed by inbox rule creation:

let risky = SigninLogs
| where RiskLevelDuringSignIn in ("medium", "high") and ResultType == "0"
| project SignInTime = TimeGenerated, UserPrincipalName, IPAddress;
OfficeActivity
| where Operation in ("New-InboxRule", "Set-InboxRule")
| join kind=inner risky on $left.UserId == $right.UserPrincipalName
| where TimeGenerated between (SignInTime .. SignInTime + 2h)
| project SignInTime, TimeGenerated, UserId, IPAddress, Parameters

Response

  1. Revoke sessions and refresh tokens.
  2. Remove inbox rules, forwarding and OAuth consents created by the attacker.
  3. Review sent mail for fraud attempts and notify recipients.
  4. Move the user to phishing-resistant MFA and compliant-device access.

Sources

  1. Source
detect mfa bypass phishing kitKali365 PhaaS2026

More on this story