THREAT-EntraID-TokenTheft Google Chronicle · YARA-L

Detect Microsoft Entra ID Session Token Theft and Replay in Google Chronicle

Session token theft (also called token replay or pass-the-cookie) is one of the most prevalent identity attacks targeting Microsoft 365 and Entra ID in 2025-2026. Adversaries use adversary-in-the-middle (AiTM) proxy frameworks (Evilginx2, Modlishka, Muraena, Tycoon 2FA, EvilProxy) to intercept valid session cookies from M365 sign-in flows, then replay those cookies to authenticate as the victim without needing their credentials or MFA code. The attack works because Microsoft's authentication cookies are bound to the browser session but not to the originating IP — replaying the cookie from a different IP is detected by Entra ID's risk engine but is not blocked by default. Scattered Spider and Storm-0539 are documented using this technique at scale against SMBs and mid-market organisations, primarily targeting financial fraud (payment diversion, payroll fraud) and IT admin compromise to then facilitate SIM swapping.

MITRE ATT&CK

Tactic
Credential Access Defense Evasion

YARA-L Detection Query

Google Chronicle (YARA-L)
yaral
rule entra_id_token_theft_replay {
  meta:
    author = "df00tech"
    description = "Detects Entra ID session token theft and replay (AiTM) via impossible travel or MFA downgrade from a new IP"
    severity = "HIGH"
    priority = "HIGH"
    mitre_attack_tactic = "Credential Access, Lateral Movement"
    mitre_attack_technique = "T1539, T1550.004"
    reference = "https://www.microsoft.com/en-us/security/blog/2022/07/12/from-cookie-theft-to-bec/"
    threat_actors = "Scattered Spider, Storm-0539, Midnight Blizzard"

  events:
    // First sign-in event (baseline)
    $signin1.metadata.event_type = "USER_LOGIN"
    $signin1.metadata.product_name = "Azure Active Directory"
    $signin1.outcome.result = "SUCCESS"
    $signin1.principal.user.email_addresses[0] = $user
    $signin1.principal.ip = $ip1
    $signin1.principal.location.country_or_region = $loc1

    // Second sign-in event (suspicious)
    $signin2.metadata.event_type = "USER_LOGIN"
    $signin2.metadata.product_name = "Azure Active Directory"
    $signin2.outcome.result = "SUCCESS"
    $signin2.principal.user.email_addresses[0] = $user
    $signin2.principal.ip = $ip2
    $signin2.principal.location.country_or_region = $loc2

    // Temporal ordering and impossible travel conditions
    $signin2.metadata.event_timestamp.seconds > $signin1.metadata.event_timestamp.seconds
    ($signin2.metadata.event_timestamp.seconds - $signin1.metadata.event_timestamp.seconds) < 3600
    ($signin2.metadata.event_timestamp.seconds - $signin1.metadata.event_timestamp.seconds) > 60
    $ip1 != $ip2
    $loc1 != $loc2

  match:
    $user over 1h

  condition:
    $signin1 and $signin2
}
high severity medium confidence

YARA-L 2.0 rule for Google Chronicle (SIEM) that detects Entra ID session token theft and replay. Correlates two successful Azure AD login events for the same user within a 1-hour window where the source IPs and geographic locations differ — a key indicator of AiTM cookie replay used by Scattered Spider and Storm-0539.

Data Sources

Microsoft Entra ID Sign-In Logs ingested into Google Chronicle via the Entra ID Chronicle ingestion parser

Required Tables

USER_LOGIN UDM events from Azure Active Directory log source

False Positives & Tuning

  • Users on split-tunnel VPNs where IP changes between authenticated requests appear as new geographic locations
  • Corporate mobility scenarios where employees roam between office Wi-Fi and cellular networks
  • Automated service accounts or CI/CD pipelines authenticating from multiple cloud regions
  • Cloud proxy or CASB solutions that rotate egress IPs transparently
  • Users in border regions whose IP geolocation alternates between two country codes

Other platforms for THREAT-EntraID-TokenTheft


Testing Methodology

Validate this detection against 1 adversary technique from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Session Cookie Replay using Evilginx2 Captured Cookie

    Expected signal: Azure AD Sign-in logs record a session established from the test IP without MFA, using the replayed cookie. Entra ID Identity Protection may generate an 'Unfamiliar sign-in properties' risk event.


Response Playbook

Triage

  1. Immediately check Entra ID Identity Protection risk events for the user (Azure AD > Security > Identity Protection > Risky sign-ins). Microsoft's own risk engine may have already flagged this as 'Anonymous IP address', 'Unfamiliar sign-in properties', or 'Impossible travel'.
  2. Determine whether Conditional Access evaluated and allowed the sign-in. If CA should have blocked the risky sign-in but didn't, investigate the CA policy configuration (is Identity Protection risk evaluated by CA?).
  3. Identify the application the token was issued for — AiTM token theft most commonly targets: Microsoft 365 (EWS, Graph), SharePoint, or Teams. The application name in the sign-in log indicates what the attacker accessed.
  4. Review MailItemsAccessed audit log for the user in the 24 hours post-compromise to determine if email was accessed by the attacker. Cross-reference the attacker IP against the Entra ID sign-in logs.
  5. Determine the vector: did the user receive and interact with an AiTM phishing email? Check email received in the 24 hours before the suspicious sign-in for links to lookalike Microsoft login pages.

Containment

  1. Immediately revoke all refresh tokens: Azure AD > Users > [User] > Revoke sessions. This invalidates all active sessions and forces re-authentication. Confirm with PowerShell: Revoke-AzureADUserAllRefreshToken.
  2. Block the attacker IP address(es) in Entra ID Named Locations and create a Conditional Access policy to block sign-in from those IPs.
  3. Reset the user's password (even though password was not stolen, this forces session invalidation).
  4. Require re-registration of MFA devices for the affected user to prevent attacker-registered MFA methods.
  5. Enable Entra ID Identity Protection Conditional Access risk policies: require MFA on medium+ risk and block on high risk sign-ins.

Evidence Collection

  1. Azure AD Sign-in logs with all fields for the incident window
  2. Entra ID Identity Protection risk events for the affected user
  3. O365 MailItemsAccessed audit events
  4. Conditional Access evaluation logs for the suspicious sign-in
  5. Network logs from corporate proxy/firewall showing user activity before the phishing click

Escalation Criteria

  • !Attacker accessed financial applications, HR systems, or executive mailboxes
  • !OAuth consent granted to third-party applications by the compromised account
  • !Evidence of internal phishing from the compromised account
  • !Attacker MFA methods registered on the account (attacker persistence)
  • !SharePoint or OneDrive data access suggesting sensitive file exfiltration

Investigation Guide

Related Techniques

Forensic Artifacts

  • >Azure AD Sign-in logs with IP, UserAgent, AuthenticationDetails
  • >Identity Protection risk event details including IP reputation and geolocation
  • >O365 MailItemsAccessed events with ClientIPAddress and OperationProperties
  • >Browser forensics on victim endpoint: history, cookies, downloaded files from phishing proxy
  • >Email headers of phishing message containing AiTM proxy link

Tuning Guidance

Token theft detection produces the most actionable results when combined with Entra ID Identity Protection risk policies. If Identity Protection is licensed, enable risk-based Conditional Access policies to automatically block high-risk sign-ins rather than just alerting. The impossible travel logic can be tuned by adding an exclusion list for users with known travel patterns or VPN use. Consider using Named Locations in Conditional Access to define expected countries for sign-in, which reduces false positives significantly for most SMBs.


Hunting Queries

Hunt for users with medium/high-risk sign-ins that Conditional Access did not block — these represent gaps in your Identity Protection enforcement that should be remediated.

Hunting — KQL
kql
AADSignInLogs
| where TimeGenerated > ago(7d)
| where Status.errorCode == 0
| where RiskLevelDuringSignIn in ("medium", "high")
| where ConditionalAccessStatus !in ("success")  // CA didn't block a risky sign-in
| summarize RiskySignIns=count(), Apps=make_set(AppDisplayName)
  by UserPrincipalName, bin(TimeGenerated, 1d)
| sort by RiskySignIns desc
Hunting — SPL
spl
index=azure sourcetype="azure:aad:signin" properties.status.error_code=0
  properties.risk_level_during_sign_in IN ("medium", "high")
  NOT properties.conditional_access_status="success"
| stats count AS RiskySignIns, values(properties.app_display_name) AS Apps
  BY properties.user_principal_name, _time span=1d
| sort - RiskySignIns

Atomic Red Team Tests

Test 1 Session Cookie Replay using Evilginx2 Captured Cookie
linux

Simulates token replay by extracting a valid Microsoft session cookie from a captured Evilginx2 phishing session and replaying it from a different IP address using a browser automation tool.

Command

bash
python3 -c "import requests; s = requests.Session(); s.cookies.set('ESTSAUTH', '<stolen_cookie>', domain='outlook.office.com'); r = s.get('https://outlook.office.com/mail/'); print(f'Status: {r.status_code}')"

Expected Telemetry

Azure AD Sign-in logs record a session established from the test IP without MFA, using the replayed cookie. Entra ID Identity Protection may generate an 'Unfamiliar sign-in properties' risk event.

Expected Detection

Alert fires on single-factor authentication from new IP not in user's 30-day baseline.

Related Detections