MFA Fatigue Push Flooding via Okta/Azure MFA Agent High-Frequency Auth

This rule detects potential brute force or password spraying attacks by monitoring high volumes of authentication failures on an endpoint within a 5-minute window. Additionally, it identifies the execution of processes associated with multi-factor authentication (MFA) or single sign-on (SSO) clients, which could indicate an adversary attempting to bypass or manipulate MFA mechanisms.