Detecting Session Token Theft HAR Files: Entra Sign-In Logs and Sentinel KQL
Retrospective: this article looks back at events from October 2023, written in 2026 with the benefit of hindsight.
Session tokens taken from HAR files, infostealer logs or phishing proxies are used to access accounts without signing in. Detection focuses on session reuse from unexpected contexts.
Signals worth watching
- A session (same session ID) used from a different IP address, ASN or country than where it began.
- Admin console access with no recent interactive sign-in or MFA.
- Activity from a device or browser that doesn't match the original sign-in's device details.
- Entra ID Protection detections: anomalous token, token issuer anomaly, attacker in the middle.
- Vendor notifications of support system compromise.
Where the data lives
- Entra ID interactive and non-interactive sign-in logs (including
SessionId). - Identity Protection risk detections.
- Admin audit logs from your identity provider and SaaS apps.
A starting query
Sessions spanning multiple ASNs:
union SigninLogs, AADNonInteractiveUserSignInLogs
| where ResultType == "0" and isnotempty(SessionId)
| summarize ASNs = dcount(AutonomousSystemNumber), IPs = make_set(IPAddress, 10),
Apps = make_set(AppDisplayName, 10) by UserPrincipalName, SessionId
| where ASNs > 1
Mobile users switching between Wi-Fi and cellular will appear; prioritize admin accounts and hosting-provider ASNs.
Response
- Revoke all sessions for the user.
- Review admin actions taken during the suspicious session.
- Identify the token source (support upload, infostealer, phishing).
- Enable token protection and stricter session controls for affected roles.
- Okta Support System Breach (Oct 2023): Session Tokens in Uploaded HAR Files Incident Teardowns
- How to Sanitize Support Uploads and Bind Tokens to Devices How-To & Hardening
- CIO Brief: Your Identity Provider's Breach Is Your Breach CIO Briefings