Detect Microsoft Entra ID Session Token Theft and Replay in Google Chronicle
Session token theft (also called token replay or pass-the-cookie) is one of the most prevalent identity attacks targeting Microsoft 365 and Entra ID in 2025-2026. Adversaries use adversary-in-the-middle (AiTM) proxy frameworks (Evilginx2, Modlishka, Muraena, Tycoon 2FA, EvilProxy) to intercept valid session cookies from M365 sign-in flows, then replay those cookies to authenticate as the victim without needing their credentials or MFA code. The attack works because Microsoft's authentication cookies are bound to the browser session but not to the originating IP — replaying the cookie from a different IP is detected by Entra ID's risk engine but is not blocked by default. Scattered Spider and Storm-0539 are documented using this technique at scale against SMBs and mid-market organisations, primarily targeting financial fraud (payment diversion, payroll fraud) and IT admin compromise to then facilitate SIM swapping.
MITRE ATT&CK
- Tactic
- Credential Access Defense Evasion
YARA-L Detection Query
rule entra_id_token_theft_replay {
meta:
author = "df00tech"
description = "Detects Entra ID session token theft and replay (AiTM) via impossible travel or MFA downgrade from a new IP"
severity = "HIGH"
priority = "HIGH"
mitre_attack_tactic = "Credential Access, Lateral Movement"
mitre_attack_technique = "T1539, T1550.004"
reference = "https://www.microsoft.com/en-us/security/blog/2022/07/12/from-cookie-theft-to-bec/"
threat_actors = "Scattered Spider, Storm-0539, Midnight Blizzard"
events:
// First sign-in event (baseline)
$signin1.metadata.event_type = "USER_LOGIN"
$signin1.metadata.product_name = "Azure Active Directory"
$signin1.outcome.result = "SUCCESS"
$signin1.principal.user.email_addresses[0] = $user
$signin1.principal.ip = $ip1
$signin1.principal.location.country_or_region = $loc1
// Second sign-in event (suspicious)
$signin2.metadata.event_type = "USER_LOGIN"
$signin2.metadata.product_name = "Azure Active Directory"
$signin2.outcome.result = "SUCCESS"
$signin2.principal.user.email_addresses[0] = $user
$signin2.principal.ip = $ip2
$signin2.principal.location.country_or_region = $loc2
// Temporal ordering and impossible travel conditions
$signin2.metadata.event_timestamp.seconds > $signin1.metadata.event_timestamp.seconds
($signin2.metadata.event_timestamp.seconds - $signin1.metadata.event_timestamp.seconds) < 3600
($signin2.metadata.event_timestamp.seconds - $signin1.metadata.event_timestamp.seconds) > 60
$ip1 != $ip2
$loc1 != $loc2
match:
$user over 1h
condition:
$signin1 and $signin2
} YARA-L 2.0 rule for Google Chronicle (SIEM) that detects Entra ID session token theft and replay. Correlates two successful Azure AD login events for the same user within a 1-hour window where the source IPs and geographic locations differ — a key indicator of AiTM cookie replay used by Scattered Spider and Storm-0539.
Data Sources
Required Tables
False Positives & Tuning
- Users on split-tunnel VPNs where IP changes between authenticated requests appear as new geographic locations
- Corporate mobility scenarios where employees roam between office Wi-Fi and cellular networks
- Automated service accounts or CI/CD pipelines authenticating from multiple cloud regions
- Cloud proxy or CASB solutions that rotate egress IPs transparently
- Users in border regions whose IP geolocation alternates between two country codes
Other platforms for THREAT-EntraID-TokenTheft
Testing Methodology
Validate this detection against 1 adversary technique from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Session Cookie Replay using Evilginx2 Captured Cookie
Expected signal: Azure AD Sign-in logs record a session established from the test IP without MFA, using the replayed cookie. Entra ID Identity Protection may generate an 'Unfamiliar sign-in properties' risk event.
Response Playbook
Triage
- Immediately check Entra ID Identity Protection risk events for the user (Azure AD > Security > Identity Protection > Risky sign-ins). Microsoft's own risk engine may have already flagged this as 'Anonymous IP address', 'Unfamiliar sign-in properties', or 'Impossible travel'.
- Determine whether Conditional Access evaluated and allowed the sign-in. If CA should have blocked the risky sign-in but didn't, investigate the CA policy configuration (is Identity Protection risk evaluated by CA?).
- Identify the application the token was issued for — AiTM token theft most commonly targets: Microsoft 365 (EWS, Graph), SharePoint, or Teams. The application name in the sign-in log indicates what the attacker accessed.
- Review MailItemsAccessed audit log for the user in the 24 hours post-compromise to determine if email was accessed by the attacker. Cross-reference the attacker IP against the Entra ID sign-in logs.
- Determine the vector: did the user receive and interact with an AiTM phishing email? Check email received in the 24 hours before the suspicious sign-in for links to lookalike Microsoft login pages.
Containment
- Immediately revoke all refresh tokens: Azure AD > Users > [User] > Revoke sessions. This invalidates all active sessions and forces re-authentication. Confirm with PowerShell: Revoke-AzureADUserAllRefreshToken.
- Block the attacker IP address(es) in Entra ID Named Locations and create a Conditional Access policy to block sign-in from those IPs.
- Reset the user's password (even though password was not stolen, this forces session invalidation).
- Require re-registration of MFA devices for the affected user to prevent attacker-registered MFA methods.
- Enable Entra ID Identity Protection Conditional Access risk policies: require MFA on medium+ risk and block on high risk sign-ins.
Evidence Collection
- Azure AD Sign-in logs with all fields for the incident window
- Entra ID Identity Protection risk events for the affected user
- O365 MailItemsAccessed audit events
- Conditional Access evaluation logs for the suspicious sign-in
- Network logs from corporate proxy/firewall showing user activity before the phishing click
Escalation Criteria
- !Attacker accessed financial applications, HR systems, or executive mailboxes
- !OAuth consent granted to third-party applications by the compromised account
- !Evidence of internal phishing from the compromised account
- !Attacker MFA methods registered on the account (attacker persistence)
- !SharePoint or OneDrive data access suggesting sensitive file exfiltration
Investigation Guide
Related Techniques
Forensic Artifacts
- >
Azure AD Sign-in logs with IP, UserAgent, AuthenticationDetails - >
Identity Protection risk event details including IP reputation and geolocation - >
O365 MailItemsAccessed events with ClientIPAddress and OperationProperties - >
Browser forensics on victim endpoint: history, cookies, downloaded files from phishing proxy - >
Email headers of phishing message containing AiTM proxy link
Tuning Guidance
Token theft detection produces the most actionable results when combined with Entra ID Identity Protection risk policies. If Identity Protection is licensed, enable risk-based Conditional Access policies to automatically block high-risk sign-ins rather than just alerting. The impossible travel logic can be tuned by adding an exclusion list for users with known travel patterns or VPN use. Consider using Named Locations in Conditional Access to define expected countries for sign-in, which reduces false positives significantly for most SMBs.
Hunting Queries
Hunt for users with medium/high-risk sign-ins that Conditional Access did not block — these represent gaps in your Identity Protection enforcement that should be remediated.
AADSignInLogs
| where TimeGenerated > ago(7d)
| where Status.errorCode == 0
| where RiskLevelDuringSignIn in ("medium", "high")
| where ConditionalAccessStatus !in ("success") // CA didn't block a risky sign-in
| summarize RiskySignIns=count(), Apps=make_set(AppDisplayName)
by UserPrincipalName, bin(TimeGenerated, 1d)
| sort by RiskySignIns desc index=azure sourcetype="azure:aad:signin" properties.status.error_code=0
properties.risk_level_during_sign_in IN ("medium", "high")
NOT properties.conditional_access_status="success"
| stats count AS RiskySignIns, values(properties.app_display_name) AS Apps
BY properties.user_principal_name, _time span=1d
| sort - RiskySignIns Atomic Red Team Tests
Simulates token replay by extracting a valid Microsoft session cookie from a captured Evilginx2 phishing session and replaying it from a different IP address using a browser automation tool.
Command
python3 -c "import requests; s = requests.Session(); s.cookies.set('ESTSAUTH', '<stolen_cookie>', domain='outlook.office.com'); r = s.get('https://outlook.office.com/mail/'); print(f'Status: {r.status_code}')" Expected Telemetry
Azure AD Sign-in logs record a session established from the test IP without MFA, using the replayed cookie. Entra ID Identity Protection may generate an 'Unfamiliar sign-in properties' risk event.
Expected Detection
Alert fires on single-factor authentication from new IP not in user's 30-day baseline.