BlueKit rrweb BitM relay traffic followed by successful sign-in

Detects activity associated with the 'BlueKit' session relay tool, which uses the rrweb library to capture and replay user session interactions. This rule identifies web browser network events involving rrweb-related scripts occurring within 10 minutes of a successful user sign-in, indicating a potential Adversary-in-the-Middle (AiTM) phishing attack where credentials and session cookies are being captured.