Failed RDP Brute Force Logon Attempts via Remote Interactive Logon Failures
Detects potential Remote Desktop Protocol (RDP) brute force campaigns by aggregating Windows Event ID 4625 (logon failure) with Logon Type 10. The rule triggers when a significant number of failed authentication attempts against a single target account and host are observed within a 1-hour window.
Microsoft Sentinel (KQL)

