AiTM/Device-Code Phishing Leading to Identity Session Takeover

This rule detects potential brute force or account compromise attempts by identifying user accounts that have successfully authenticated or initiated authentication events from two or more distinct IP addresses within the observed time window. It monitors Windows Event IDs 4624 (Successful Logon), 4648 (Logon attempted using explicit credentials), and 4776 (The domain controller attempted to validate the credentials for an account).