Service Account Login from External or Anomalous Source IPs
Detects successful authentication events from accounts identified as service, managed, or robot accounts (e.g., svc_, sa_, msol, robot) originating from external IP addresses or exhibiting an unusually high number of distinct source IP addresses. This behavior is indicative of potential credential theft, token replay attacks, or unauthorized usage of service account identities.
SentinelOne

