Detection Engineering
Session Hijacking Detection
Session hijacking detection after MFA. Refresh-token reuse, device drift, and impossible travel, with SPL, KQL, and Sigma analytics plus a triage runbook.
2 articles
Session hijacking detection after MFA. Refresh-token reuse, device drift, and impossible travel, with SPL, KQL, and Sigma analytics plus a triage runbook.
An OAuth misconfiguration defensive review — redirect_uri validation, PKCE and state, detecting off-allowlist redirects and token anomalies, aligned to RFC 9700.