Microsoft Entra Suspicious or Automated User-Agent Sign-In

Detects sign-in activity within Microsoft Entra ID characterized by User-Agent strings indicative of automated tools, command-line HTTP clients, and security testing software. This rule is designed for anomaly detection and necessitates correlation with other context such as source IP, authentication results, and user behavior to identify potential malicious activity.