Edge Device Exploitation: Auth from Network Device IPs - T1190 T1078.002
This rule detects successful authentication attempts directed at network devices from sources not explicitly marked as authorized management systems. It identifies users or systems that are not recognized service accounts authenticating against network infrastructure and flags activity that involves multiple unique destination targets as high risk.
Splunk (SPL)

