MSSQL SA Account Successful Login After Brute-Force Attempt
Detects a successful authentication to Microsoft SQL Server using the 'sa' account from a non-local address. This rule is designed to alert on potentially unauthorized access following a brute-force attack, as identified by the correlation of high-volume authentication failures (Event ID 18456) followed by a successful login (Event ID 18453/18454).
Sigma

