Credential Theft via Failed Logons (Brute Force or Password Spraying)

This rule detects multiple failed logon attempts (more than 5 within a 5-minute window) for user accounts from a single IP address. This behavior is indicative of a brute-force attack or password guessing attempt against user accounts.