Silver Pass-ta-key - Device/UV Key Registration Followed by High-Value Account Login

Detects the Silver Pass-ta-key attack chain where a device or UV key registration event (device/register, keys/genpair, device/add_uv_key) on the cloud authenticator is followed within a short window by a successful login to a high-value account from a device with no prior authentication history. To reduce false positives from legitimate device enrollment-then-use, the rule additionally requires either that the registration lacked an expected attestation/biometric ceremony, or that the subsequent login originated from a geolocation/ASN inconsistent with the user's normal authentication pattern, consistent with fully automated authentication using an attacker-registered UV key without human interaction.