Microsoft 365Detection & ResponseRetrospectives

Detecting AiTM Session Cookie Theft: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2022, written in 2026 with the benefit of hindsight.

AiTM phishing produces a valid session from an attacker's infrastructure. Detection focuses on session anomalies and the business email compromise that often follows.

Signals worth watching

  • Entra ID Protection detections: Attacker in the Middle, Anomalous token, Unfamiliar sign-in properties.
  • A user signing in successfully, then the same session appearing from a different IP or hosting provider within minutes.
  • Sign-ins to Microsoft 365 from IPs associated with known phishing infrastructure.
  • New inbox rules that move or delete messages (keywords like "invoice," "payment," or rules that mark as read and move to RSS Feeds or Archive).
  • Mailbox access followed by emails sent to external finance contacts.
  • Defender XDR alerts correlating a phishing URL click with a suspicious sign-in.

Where the data lives

  • Entra ID sign-in logs and Identity Protection.
  • Defender for Office 365 URL click events.
  • Unified audit log for inbox rules and mailbox activity.

A starting query

Suspicious inbox rules:

OfficeActivity
| where Operation in ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules")
| where Parameters has_any ("DeleteMessage", "MoveToFolder", "MarkAsRead")
| where Parameters has_any ("invoice", "payment", "wire", "bank", "RSS", "Archive")
| project TimeGenerated, UserId, ClientIP, Operation, Parameters

Response

  1. Revoke sessions and reset credentials.
  2. Remove malicious inbox rules and forwarding.
  3. Review sent messages and notify external parties of potential fraud.
  4. Move the user to phishing-resistant MFA.
detect aitm session cookie theftAiTM phishing campaign2022

More on this story