Password Spraying via RDP/SMB/WinRM - High Distinct Account Failures
Detects potential password spraying or brute force activity by monitoring Windows Event Code 4625. The rule identifies source IP addresses that have attempted to authenticate against more than 10 unique accounts within a 5-minute window, calculating a spray ratio to differentiate high-intensity credential spraying attempts.
Splunk (SPL)

