High Volume Login Attempts to Web Application

This rule detects a high volume of POST requests to login, authentication, or password-related URI stems within a 5-minute window from unique IP addresses. This behavior is indicative of brute-force attacks or credential stuffing attempts against web applications.