Fancy Bear OAuth Abuse

This rule detects successful sign-ins using OAuth from residential IP addresses. It joins `SigninLogs` with `IdentityLogonEvents` to correlate successful OAuth authentications with user logon events. The intent is to identify potentially suspicious access, possibly indicating credential abuse or unauthorized access attempts from non-corporate or unexpected locations.