2026 Critical Enterprise Intrusion Chain Detection: Cloud Sign-In from New Geo/ASN After Endpoint Credential-Theft Alert

This rule correlates endpoint-based alerts related to credential theft or infostealer malware with subsequent successful cloud identity authentication events. It identifies situations where a user, who has recently triggered a credential theft alert on an endpoint, logs into a cloud environment from a country or IP address that has not been historically associated with that user within a 24-hour window.