HomeAlertsCASE-5504
Back to Alerts

Azure AD sign-in for taylor.kim blocked — token replay attack pattern detected

CriticalAI ReadyMatters AI already took action automatically. Review and confirm, or override.User: taylor.kim@acme-corp.comDetected: 35 min ago
True positiveAutomated containment applied

Microsoft Entra ID (Azure AD) detected a token replay attack against taylor.kim@acme-corp.com at 10:35. An attacker obtained a valid session token (likely via AiTM phishing) and replayed it from IP 104.21.88.12 (Cloudflare proxy · Netherlands). The legitimate user was simultaneously authenticated from her known MacBook in London. Microsoft Identity Protection scored the sign-in as 'High Risk' (93% confidence) and Conditional Access automatically blocked the suspicious session and forced password reset. The phishing email that delivered the AiTM kit has been quarantined from the mail gateway.

WHY FLAGGED
Concurrent sessions from London (known device) and Netherlands (proxy · unknown device) on same account
Token replay signature: session token used from a different IP than the one that authenticated
Microsoft Identity Protection risk score: High (93%) — AiTM phishing pattern
Alert Info
Assigned to
Unassigned
Alert ID
CASE-5504
AI Investigation
Automated containment applied
Alerts
1 linked
Detection
Datastore types
Azure AD, Okta
Policy
Risk type
Credential Misuse
User
User
Taylor Kimtaylor.kim@acme-corp.com
Employee ID
ACME008834
Department
Legal
Employment
Active
Ask Matters AI
Hi, I'm Matters AI. Ask me about your alerts, cases, or policies.