performing-adversary-in-the-middle-phishing-detection - Detect and respond to AiTM phishing attacks.
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits to bypass MFA and steal session tokens.
Tags
Updated: 2026-09-17Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Deploy phishing resistant MFA
- Configure Conditional Access policies
- Build AiTM detection rules
- Monitor web proxy for AiTM
- Implement post compromise detection
Inputs
- Azure AD sign in logs
- Web proxy SSL inspection logs
- Threat intelligence feeds
Outputs
- SIEM detection alerts
- Blocked proxy connection logs
- Revoked session tokens
Requirements
- Azure AD or Entra ID
- SIEM with authentication log ingestion
- Web proxy with SSL inspection
- Endpoint Detection and Response solution
