A new hunting method shows how defenders can detect suspected device code phishing by correlating Entra ID sign-in telemetry with web activity immediately preceding a Device Code authentication. The approach uses the Cmsi:Cmsi endpoint call in sign-in events as the anchor for Device Code logins, then looks back five minutes to identify the last three URLs visited by the same user in DeviceNetworkEvents, helping investigators reconstruct the browsing sequence that led to the authentication.
The technique is designed to surface suspicious behavior without depending on known malicious domains or threat intelligence feeds. It enriches remote IP addresses with country data and filters out expected Microsoft services, common websites, and approved geographies so analysts can focus on unusual browsing patterns that may indicate previously unknown phishing infrastructure rather than treating every Device Code authentication as malicious.

See real exploitation activity before you spend the cycle.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.