Detecting MFA Bypass Phishing Kit: Defender XDR and Sentinel Hunting Queries
Token theft through phishing kits produces sessions that look legitimate but come from attacker infrastructure. These detections help find them.
Signals worth watching
- Entra ID Protection detections: Anomalous token, Attacker in the middle, Unfamiliar sign-in properties, Token issuer anomaly.
- Sessions used from an IP or ASN different from where they started, especially hosting providers.
- Device code sign-ins outside approved accounts.
- Non-compliant or unregistered devices accessing mail after a sign-in from a compliant device.
- Mailbox activity — inbox rules, mass reads, external forwarding — shortly after a new session.
Where the data lives
- Entra ID sign-in logs (interactive and non-interactive) and Identity Protection.
- Unified audit log and Defender XDR (CloudAppEvents).
- Defender for Office 365 URL click data, to find the phishing message.
A starting query
Risky sign-ins followed by inbox rule creation:
let risky = SigninLogs
| where RiskLevelDuringSignIn in ("medium", "high") and ResultType == "0"
| project SignInTime = TimeGenerated, UserPrincipalName, IPAddress;
OfficeActivity
| where Operation in ("New-InboxRule", "Set-InboxRule")
| join kind=inner risky on $left.UserId == $right.UserPrincipalName
| where TimeGenerated between (SignInTime .. SignInTime + 2h)
| project SignInTime, TimeGenerated, UserId, IPAddress, Parameters
Response
- Revoke sessions and refresh tokens.
- Remove inbox rules, forwarding and OAuth consents created by the attacker.
- Review sent mail for fraud attempts and notify recipients.
- Move the user to phishing-resistant MFA and compliant-device access.