Entra ID & IdentityDetection & ResponseRetrospectives

Detecting SMS Phishing Credential Harvesting: Entra Sign-In Logs and Sentinel KQL

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2022, written in 2026 with the benefit of hindsight.

SMS phishing campaigns like 0ktapus harvest credentials and MFA codes through fake sign-in pages. Detection focuses on the sign-ins that follow.

Signals worth watching

  • Successful sign-ins shortly after a user received suspicious SMS messages (often learned from user reports).
  • Sign-ins from new IPs or devices that complete MFA with one-time codes, especially from hosting providers or VPN services.
  • Multiple employees' accounts signing in from the same unfamiliar IP within a short time.
  • New MFA methods registered right after a suspicious sign-in.
  • Entra ID Protection detections for attacker-in-the-middle activity or anomalous tokens.

Where the data lives

  • Entra ID sign-in logs and audit logs.
  • Identity Protection risk detections.
  • User reports to the security team (create an easy reporting channel for SMS phishing).

A starting query

Multiple users signing in from the same new IP:

SigninLogs
| where TimeGenerated > ago(1d) and ResultType == "0"
| summarize Users = dcount(UserPrincipalName), UserList = make_set(UserPrincipalName, 20)
    by IPAddress, AutonomousSystemNumber
| where Users >= 3

Exclude known corporate egress IPs.

Response

  1. Revoke sessions and reset credentials for affected users.
  2. Remove any MFA methods registered by the attacker.
  3. Block the IP range and phishing domains.
  4. Notify staff about the active campaign.
  5. Accelerate FIDO2 or passkey rollout for targeted groups.
detect sms phishing credential harvesting0ktapus / Twilio2022

More on this story