Device Code Phishing - PaaS and Login Correlation Base

Identifies web requests to commonly abused PaaS platforms (Cloudflare Workers, Vercel, AWS Amplify) or the Microsoft device login endpoint. This rule acts as a base to identify specific events for downstream correlation. To properly detect a device code phishing sequence (such as EvilTokens), correlate a PaaS access event followed by a device login event from the same Source IP within a 5-minute window.