AiTM reverse-proxy phishing kit relaying Microsoft ESTS session cookie from non-Microsoft domain

Detects network traffic associated with Adversary-in-the-Middle (AiTM) phishing kits that impersonate Microsoft and Google login pages. The rules identify the presence of specific HTML elements (like Cloudflare Turnstile anti-bot gates) and authentication session cookie headers served from non-authorized/non-official domains, indicating a reverse-proxy phishing attack.