External Remote Access: Failed Logons Then Success from Uncommon IP
Detects a pattern of multiple failed authentication attempts (brute force) from an external IP address followed by a successful authentication event on remote access services such as RDP, VPN, or NTLM. The rule filters for non-private IP addresses and flags successes occurring outside of standard business hours.
Microsoft Sentinel (KQL)

