Detecting AiTM Session Cookie Theft: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from July 2022, written in 2026 with the benefit of hindsight.
AiTM phishing produces a valid session from an attacker's infrastructure. Detection focuses on session anomalies and the business email compromise that often follows.
Signals worth watching
- Entra ID Protection detections: Attacker in the Middle, Anomalous token, Unfamiliar sign-in properties.
- A user signing in successfully, then the same session appearing from a different IP or hosting provider within minutes.
- Sign-ins to Microsoft 365 from IPs associated with known phishing infrastructure.
- New inbox rules that move or delete messages (keywords like "invoice," "payment," or rules that mark as read and move to RSS Feeds or Archive).
- Mailbox access followed by emails sent to external finance contacts.
- Defender XDR alerts correlating a phishing URL click with a suspicious sign-in.
Where the data lives
- Entra ID sign-in logs and Identity Protection.
- Defender for Office 365 URL click events.
- Unified audit log for inbox rules and mailbox activity.
A starting query
Suspicious inbox rules:
OfficeActivity
| where Operation in ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules")
| where Parameters has_any ("DeleteMessage", "MoveToFolder", "MarkAsRead")
| where Parameters has_any ("invoice", "payment", "wire", "bank", "RSS", "Archive")
| project TimeGenerated, UserId, ClientIP, Operation, Parameters
Response
- Revoke sessions and reset credentials.
- Remove malicious inbox rules and forwarding.
- Review sent messages and notify external parties of potential fraud.
- Move the user to phishing-resistant MFA.