Plan
active
Greatness PhaaS expands to AiTM and device-code attacks on M365
- Engineer — Plan: AiTM and device-code phishing bypass standard MFA; audit your M365 conditional access policies to restrict or block device code flow, and prioritize phishing-resistant MFA (FIDO2 or certificate-based) for privileged accounts this quarter.
- SOC/IR — Plan: Build or tune detections for suspicious device-code OAuth grant flows and anomalous session token reuse in Entra ID / M365 audit logs — the AiTM component means valid MFA completion is not a reliable innocence signal.
- Leader — Learn: Confirms that commodity phishing platforms are now routing around standard MFA at scale; useful background when justifying a phishing-resistant MFA upgrade on the roadmap or fielding customer security questionnaires about M365 identity controls.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.