Password Spraying Against Active Directory Accounts
Detects high-volume authentication failures originating from a single IP address with a large number of unique target accounts within a 30-minute window, indicative of a password spraying or brute force attack against network services.
Microsoft Sentinel (KQL)

