Password Spraying Against Active Directory Accounts

Detects high-volume authentication failures originating from a single IP address with a large number of unique target accounts within a 30-minute window, indicative of a password spraying or brute force attack against network services.