Files
Samirbous f0012d8770 [New] Entra ID Microsoft Authentication Broker DRS Sign-In from Susp ASN (#6190)
* [New] Entra ID Microsoft Authentication Broker DRS Sign-In from Suspicious ASN

Detects Microsoft Entra ID sign-in activity where the Microsoft Authentication Broker requests the Device Registration Service from a source autonomous system number (ASN) associated with VPN, residential proxy, or hosting egress commonly observed in OAuth phishing and adversary-in-the-middle device registration flows. This pattern can indicate device join or primary refresh token acquisition staged from attacker-controlled infrastructure after a user completes
authentication.

* Update persistence_entra_id_microsoft_auth_broker_drs_signin_from_suspicious_asn.toml
2026-06-05 17:35:26 -04:00
..
2025-07-07 11:27:48 -04:00