Non-Interactive Sign-In Spike from Unseen App/Device (Refresh Token Abuse)

This rule monitors Azure AD and Office 365 non-interactive sign-in logs to identify anomalous spikes in activity from previously unseen applications or devices. It uses a 30-day baseline to determine if a sign-in pair (User/App/Device) is known. It further flags sign-ins from unrecognized locations (ASN/Country), flagging them with higher severity. This behavior is often indicative of automated credential abuse or token exploitation.