Successful Sign-In Following Potential Password Spray from Unknown ASN
This rule detects successful sign-in events originating from IP addresses that have previously demonstrated a password-spraying pattern (multiple failed sign-ins across distinct accounts within a two-hour window). To reduce noise, it excludes successful logins originating from 'known' Autonomous System Numbers (ASNs) where at least 10 distinct users have historically authenticated successfully. The detection further filters for sessions lacking managed device identifiers and allows for manual exclusion of specific applications, IP addresses, or geographic locations.
Microsoft Sentinel (KQL)
