Sign-in from IP Associated with Recognized Attacker Infrastructure

This rule identifies sign-in events or alerts that are explicitly flagged by security intelligence as originating from IP addresses associated with known malicious or attacker infrastructure.