Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11An adversary-in-the-middle (AiTM) phishing attack can capture an authenticated session even after you complete multi-factor authentication (MFA). The attacker relays your sign-in through a fake site, then may reuse the session cookie or token it obtains. To respond, investigate the session and any activity that followed, contain confirmed compromise, and move protected sign-ins to phishing-resistant authentication such as FIDO2/WebAuthn security keys or supported passkeys.
How an AiTM attack gets around MFA
An AiTM phishing site acts as a live proxy between you and a legitimate service. You enter your password and complete a second factor on the relayed page; the real service may authenticate the session, while the attacker captures its session cookie or token. The attacker can then try to reuse that authenticated session without repeating the original sign-in. Microsoft describes this proxy-and-cookie theft pattern in its AiTM investigation guidance and token theft playbook.
This does not mean every MFA method is defeated in the same way, or that MFA is useless. It means a completed MFA challenge is not proof that the resulting session is safe. Codes and approval prompts can be relayed or socially engineered; phishing-resistant authentication is designed to resist that kind of credential relay.
How to spot a suspected stolen session
Start with the report or alert: a user who entered credentials on a suspicious page, a suspicious link or email, an identity-provider alert, or an unfamiliar sign-in. Compare the affected account’s sign-ins with its normal pattern. Review unusual locations, devices, sign-in properties, and non-interactive sign-ins; Microsoft also recommends reviewing anomalous-token alerts and attempted access to Windows Primary Refresh Tokens.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Trace the session and what happened next
- Connect sign-in records and session IDs to later cloud activity. Look for the same session appearing from changing or unexpected locations.
- Check for newly registered devices, added MFA or passwordless credentials, and password or other credential changes.
- Review unusual or bulk file downloads, increased mail access, suspicious mailbox searches, mail deletion, and new inbox forwarding rules.
- Examine the suspicious URL, email delivery and click data, and related endpoint activity. Search for other messages containing the same URL and clicks from different IP addresses.
- Correlate identity, email, endpoint, and cloud audit timelines. An unfamiliar sign-in can have a legitimate explanation, so verify it with the user and organizational context. If suspicious activity cannot be confirmed as valid, Microsoft’s token-theft playbook advises treating it as a breach and proceeding with mitigation.
Microsoft Defender XDR users can use data such as AadSignInEventsBeta, IdentityLogonEvents, CloudAppEvents, EmailEvents, EmailUrlInfo, UrlClickEvents, and DeviceEvents to investigate. Its AiTM playbook includes example hunting queries for suspicious session geography and inbox rules associated with anomalous-token alerts. These tables and queries are specific to Microsoft tooling and may require appropriate access and licensing.
What to do if an account session is compromised
- Contain the identity. Reset the compromised account’s credentials and revoke or disable its tokens. Follow your identity provider’s procedures to invalidate active sessions.
- Remove unauthorized changes. Review and remove unfamiliar authentication methods, devices, mailbox rules, and other access or persistence changes found during investigation.
- Block the infrastructure. Block identified malicious URLs and IP addresses in applicable network protection controls. Where relevant, block associated sender IP addresses and domains.
- Find related exposure. Search for other users who received or clicked related phishing messages, and investigate the endpoints and cloud applications used during the affected session.
- Keep monitoring. Check for new sign-ins and actions after containment. A password reset alone does not show that other persistence or follow-on activity has been removed.
Prevent future AiTM attacks with phishing-resistant sign-in
Prefer phishing-resistant MFA for protected accounts and applications. CISA’s 2023 Implementing Phishing-Resistant MFA fact sheet identifies it as the strongest form among those it ranks and urges system administrators and high-value targets to implement it or plan a migration. Microsoft’s examples include FIDO2 security keys and supported passkeys. In its Secure Future Initiative material, Microsoft states: “Traditional MFA is no longer enough—phishing-resistant MFA is the new baseline.”
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Where your identity platform supports it, set an authentication-strength or equivalent access policy so protected sign-ins require the intended phishing-resistant method instead of silently accepting weaker options. Check service and platform compatibility before enforcing the policy.
Choose an option that fits your control requirements
| Option | Phishing and replay resistance | Device control and administrator visibility | Considerations |
|---|---|---|---|
| FIDO2/WebAuthn security key | Phishing-resistant sign-in | Physical key; confirm how your identity platform manages registration and use. | Requires compatible services and key provisioning, enrollment, and recovery planning. |
| Device-bound passkey | Phishing-resistant sign-in | Microsoft recommends this approach when strict device-boundary control is required. | Check support on the devices and services your organization uses. |
| Synced passkey | Phishing-resistant sign-in | Microsoft says administrators currently cannot see or control exactly which devices hold a copy of a synced passkey. | Can suit environments that accept syncing; confirm support and account recovery arrangements. |
Microsoft’s passkey guidance discusses supported passkeys, including device-bound and synced models. The choice is not simply “secure” versus “insecure”: synced passkeys retain phishing resistance, while device-bound passkeys may better fit policies requiring tighter device boundaries.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Make enrollment and recovery part of the rollout
Stage deployment across users and applications. Account for hardware provisioning, platform support differences, changes to user behavior, implementation effort, and the support users will need. Treat credential registration and recovery as part of the security boundary: Microsoft recommends secure onboarding workflows and time-bound Temporary Access Passes where appropriate. A phishing-resistant authenticator cannot protect an account if an attacker can exploit a weak registration or recovery process.
Microsoft reports that 92% of its employee productivity accounts are protected by phishing-resistant authentication methods; the page does not state a year, and this is Microsoft’s own rollout figure, not an independently verified rate for organizations generally.
Rank #4
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
Use additional controls as layers
Phishing-resistant sign-in is the central authentication defense; network controls can reduce opportunities for attackers to position themselves between a user and a service. MITRE ATT&CK’s T1557, Adversary-in-the-Middle mitigation guidance includes restricting unnecessary legacy network protocols, filtering traffic, segmenting network infrastructure, and training users to heed certificate errors. MITRE identifies the technique as version 2.5, last modified 12 May 2026. These measures complement rather than replace phishing-resistant authentication.
Quick Recap
Best Value
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems

