
EvilProxy AiTM: Indeed Redirect to M365 Cookie Theft
An executive at a logistics firm clicks a job-themed phishing link that abuses a recruiting platform's open redirect to reach an EvilProxy adversary-in-the-middle page. The page reverse-proxies the real Microsoft 365 sign-in, so the victim completes MFA against the attacker, who captures and replays the post-MFA session cookie. Work the email, web-proxy, DNS, Entra sign-in, and perimeter records to reconstruct the redirect chain, the relay infrastructure, and the MFA bypass.
Launches in 3 days
Tuesday, August 18, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
What you'll investigate
7 objectives unlock when this operation goes live.
Be first when it launches
Create your free account now. The moment this operation goes live on Aug 18, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free