High-Volume SSH Brute Force Attack Detection (FortiBleed campaign)
Detects high-volume SSH or network logon failures from a single source IP address within a short time window, indicative of a brute force attack. The rule specifically mentions consistency with 'mpbrute2.bin' tooling used in the 'FortiBleed' campaign.
Microsoft Sentinel (KQL)

