Non-interactive password spray via Azure CLI against Entra ID
This rule detects large-scale, non-interactive password-spraying campaigns targeting Microsoft Entra ID (Azure AD) accounts. It specifically identifies anomalous login behavior originating from Azure CLI or similar non-interactive clients, where a single source IP attempts to authenticate against a large number of distinct user accounts with a low number of failures per user within a short timeframe, characteristic of 'low-and-slow' password spraying.
Microsoft Sentinel (KQL)

