Identity Management (Entra ID)

AiTM Phishing: Bypassing Entra ID MFA — Akuity SOC

5 min read Akuity SOC · Delphisoft Deutschland

Discover how AiTM reverse proxies hijack ESTSAUTH cookies despite Microsoft Authenticator MFA. Detect and remediate session replay via Advanced Hunting (KQL).

Assuming that push-based multi-factor authentication (MFA) stops 99% of identity compromises has become the premier operational blind spot for CISOs. In Adversary-in-the-Middle (AiTM) attacks, threat actors no longer attempt to crack credentials or bypass authentication; they simply ask your users to authenticate on their behalf.

The Push MFA Illusion and ESTSAUTH Cookie Interception

AiTM attack frameworks (such as Evilginx or Muraena) deploy a transparent reverse proxy positioned between the victim's endpoint and genuine Microsoft Entra ID authentication endpoints. The architecture establishes two separate TLS sessions: Victim ↔ Proxy and Proxy ↔ login.microsoftonline.com, dynamically rewriting HTTP headers in flight.

When the user enters their credentials and approves the Microsoft Authenticator push prompt, the authentication sequence completes successfully on the official infrastructure. Microsoft Entra ID responds with Set-Cookie headers carrying the critical session tokens: ESTSAUTH and ESTSAUTHPERSISTENT. The proxy extracts these plaintext session tokens before forwarding traffic. Within seconds, the adversary injects the stolen cookies into their own browser profile, achieving fully authenticated session access without triggering subsequent MFA challenges, bypassing Conditional Access policies lacking strict device compliance or FIDO2 phishing resistance.

Entra ID Native Blind Spots and Manual Triage Friction

Inside the Microsoft Entra ID admin center, this compromise generates a misleading Status 0 (Success) sign-in event: "Single-factor authentication completed" followed by "MFA requirement satisfied." The intrusion blends seamlessly into normal baseline user traffic.

Triaging this activity natively forces SOC analysts to manually correlate sign-in IP addresses, user-agent anomalies, and ASN shifts across disparate logs. This manual pivot drives an average MTTR of 18 minutes. Under triage pressure, analysts frequently paste suspicious authentication strings into unsecured third-party tools such as public CyberChef instances, inadvertently leaking active corporate session tokens onto external infrastructure.

Precision Hunting: Tracking Hijacked SessionIds with Advanced Hunting (KQL)

To identify the TLS transport fork without manual overhead, SOC teams must query concurrent session usage via Advanced Hunting (KQL). Stolen cookie replay produces an immediate IP address and user-agent divergence on the same active SessionId:

let Lookback = 2h;
AADSignInEventsBeta
| where Timestamp > ago(Lookback) and ErrorCode == 0 and isnotempty(SessionId)
| summarize 
    IPCount = dcount(IPAddress),
    IPList = make_set(IPAddress, 3),
    UserAgents = make_set(UserAgent, 3),
    CountryList = make_set(Country, 3),
    FirstSeen = min(Timestamp),
    LastSeen = max(Timestamp)
    by SessionId, AccountUpn
| where IPCount > 1
| extend TimeDeltaSec = datetime_diff('second', LastSeen, FirstSeen)
| where TimeDeltaSec <= 1800
| project SessionId, AccountUpn, TimeDeltaSec, IPCount, IPList, CountryList, UserAgents
| sort by TimeDeltaSec asc

Tuning recommendation: Exclude known corporate egress subnets and secure web gateways (CASB/SASE). Focus alerts on dual IP occurrences under a 30-minute delta paired with anomalous country or ASN modifications.

Sub-Second SOAR Remediation with Akuity SOC

Akuity SOC replaces the 18-minute manual correlation cycle and mitigates token leakage risks. Within the unified Ticket Panel, the integrated AI assistant triggers the background Function Call execute_advanced_hunting_kql to expose the session fork in under 2 seconds, safely deobfuscating artefacts entirely in-app.

Response execution is immediate: with one click, the analyst invokes revokeSessions() to invalidate active refresh tokens and compromised ESTSAUTH cookies, alongside confirmUserCompromised() to transition the user to high-risk state within Microsoft Entra ID. Guardrailed by mandatory analyst MFA AAL2 elevation, every remediation step is written to an immutable audit ledger compliant with NIS 2 and SOC 2 Type II standards.

Technical FAQ

Why does Conditional Access fail to block AiTM session replay?

Unless Conditional Access mandates compliant, managed devices (via Microsoft Intune) or cryptographic phishing-resistant credentials (FIDO2 / WebAuthn), Microsoft Entra ID evaluates the injected ESTSAUTH session cookie as already fully authenticated, regardless of the client machine's identity.

How does automated session revocation differ from standard password resets?

A standard password change does not instantly terminate issued session tokens. Akuity SOC's 1-click revocation programmatically invalidates the token revocation counter and Primary Refresh Token (PRT) binding, terminating the adversary's browser session in less than one second.

Ready to eliminate AiTM session replay in 1 click? Connect Akuity SOC to your Microsoft Entra ID tenant in under 10 minutes. Start your 14-day free trial (no credit card required) or evaluate our MSSP margin simulator.

Related Solution Page

At-Risk Identity Management (Entra ID)

Block compromises instantly with Akuity SOC agentless SOAR orchestration.

Discover the complete solution