Brute Force Attack Against Domain Controller
Detects high-frequency failed logon attempts (Event ID 4625) from a single IP address within a short time window, indicating potential brute force or password spraying activity targeting Windows systems.
Microsoft Sentinel (KQL)

