Credential Theft via Failed Logons (Brute Force or Password Spraying)
This rule detects multiple failed logon attempts (more than 5 within a 5-minute window) for user accounts from a single IP address. This behavior is indicative of a brute-force attack or password guessing attempt against user accounts.
Microsoft Sentinel (KQL)

