2026 Critical Enterprise Intrusion Chain Detection: Adversary-in-the-Middle Sess
This rule detects potential Adversary-in-the-Middle (AiTM) phishing activity by identifying session token or cookie reuse. It monitors for instances where a valid authentication session is established from one IP address and then immediately used again by the same user with the same session ID from a different IP address and potentially a different User-Agent, indicating that an attacker has hijacked and replayed the MFA-satisfied session.
YARA-L

