MFA Push Bombing Success Followed by Privileged Discovery
This rule monitors for successful external logins occurring on an endpoint that previously demonstrated patterns of suspected MFA fatigue (multiple failed push notifications) and subsequent internal reconnaissance activity (execution of commands used for domain or system discovery). The rule correlates these events to identify potential compromised credentials being actively used for lateral movement or persistence.
SentinelOne

