High Volume Logon Activity Detected

This rule detects an unusually high volume of logon events (both successful and failed) or a large number of unique users attempting to log on within a 5-minute window. This behavior is indicative of potential brute-force attacks or credential stuffing attempts against Windows systems.