High Volume Login Attempts to Web Application
This rule detects a high volume of POST requests to login, authentication, or password-related URI stems within a 5-minute window from unique IP addresses. This behavior is indicative of brute-force attacks or credential stuffing attempts against web applications.
Microsoft Sentinel (KQL)

