Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

Adversary-in-the-middle (AiTM) phishing

Phishing that proxies the real Microsoft sign-in page, relaying password and MFA to steal the resulting session cookie so the attacker can bypass MFA.

Adversary-in-the-middle (AiTM) phishing places a reverse proxy between the victim and the genuine sign-in service. The victim sees the real Microsoft sign-in page through the proxy, types their password and approves MFA; the proxy relays everything and keeps the session cookie Entra ID issues. The attacker then replays that cookie from their own machine and is not asked for MFA again.

In the logs, AiTM shows as an interactive sign-in from the proxy's network (often a hosting provider), followed by token replay: non-interactive sign-ins with the same Session ID from another IP or country. Phishing-resistant MFA (passkeys, FIDO2 keys, Windows Hello for Business) is the main defence. MITRE ATT&CK: T1557 and T1550.004.

See AiTM phishing detection.