Most Popular Detection 2026: RDP Brute Force and Password Spray Attacks
This rule detects potential RDP brute force and password spraying attacks by correlating Windows Event ID 4625 (failed logins) and 4624 (successful logins) via RDP (Logon Type 10). It monitors for high volumes of failed attempts across multiple accounts or high volume of failed attempts from a single source, followed by successful authentication from the same source.
Splunk (SPL)

