Best Detection of 2026 Series: Post-AiTM Session Token Replay and Impossible Travel

Detects the reuse of a session or refresh token within a short timeframe (<= 900 seconds) where the source IP location, device identifier, or User-Agent string has materially changed. This behavior is indicative of Adversary-in-the-Middle (AiTM) attacks, where a session cookie has been stolen and replayed from an attacker's infrastructure to hijack a legitimate user's session.