MFA Fatigue / Push Bombing - High Volume Failed Logins (T1621)
Detects high-volume failed authentication attempts targeting a specific user account from a source IP address, indicative of 'MFA fatigue' or 'push bombing' attacks. This rule monitors endpoint-visible logon failure events as captured by EDR telemetry to identify potential attempts to circumvent multi-factor authentication by spamming the user with requests.
SentinelOne

