Dahua Cloud Password-Recovery Code Abuse for Unauthenticated Admin Reset

This rule monitors for two distinct stages of potential account recovery abuse. First, it detects the execution of suspected Python scripts on an endpoint that contain command-line arguments related to password recovery or authentication codes. Second, it monitors network proxy/web logs for a high volume of API requests to the 'easy4ipcloud.com' domain associated with password reset or device probe endpoints, which may indicate automated credential stuffing or unauthorized device account recovery attempts.