Username Enumeration or Brute Force via High Unique-Username Failure Rate
This rule detects potential brute force attacks or username enumeration by identifying 5-minute windows where multiple distinct user accounts trigger a high volume of failed logon events (Event ID 4625). It summarizes failures by timeframe and flags scenarios where more than 5 unique usernames failed to authenticate, categorizing the severity based on the number of accounts affected.
Microsoft Sentinel (KQL)

