Skip to main content
EvilProxy AiTM: Indeed Redirect to M365 Cookie Theft operation cover
COMING SOONIntermediate

EvilProxy AiTM: Indeed Redirect to M365 Cookie Theft

An executive at a logistics firm clicks a job-themed phishing link that abuses a recruiting platform's open redirect to reach an EvilProxy adversary-in-the-middle page. The page reverse-proxies the real Microsoft 365 sign-in, so the victim completes MFA against the attacker, who captures and replays the post-MFA session cookie. Work the email, web-proxy, DNS, Entra sign-in, and perimeter records to reconstruct the redirect chain, the relay infrastructure, and the MFA bypass.

45m
7 tasks
50 points
Free

Launches in 3 days

Aug 18, 2026

Tuesday, August 18, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

EmailSIEMFirewall

What you'll investigate

7 objectives unlock when this operation goes live.

1Open the case
2Identify the compromised account
3Trace the delivery redirect
4Pin the adversary-in-the-middle landing
5Locate the relay behind the session
6Name the interception technique
7Classify how MFA was defeated

Be first when it launches

Create your free account now. The moment this operation goes live on Aug 18, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free