TrustSink: Unfamiliar Issuer Claims Hardware Key
Detects Azure sign-in events claiming successful hardware-key or FIDO2 authentication where the authentication issuer is not part of a known-good allow-list. This behavior is indicative of a rogue MFA provider, such as the TrustSink attack, which issues forged tokens claiming MFA requirements were satisfied.
Microsoft Sentinel (KQL)

