Vikas Lokhande

@vlokhande
0 followers1 download24 copies0 likes329 views

1 detection

This rule detects successful sign-in events originating from IP addresses that have previously demonstrated a password-spraying pattern (multiple failed sign-ins across distinct accounts within a two-hour window). To reduce noise, it excludes successful logins originating from 'known' Autonomous System Numbers (ASNs) where at least 10 distinct users have historically authenticated successfully. The detection further filters for sessions lacking managed device identifiers and allows for manual exclusion of specific applications, IP addresses, or geographic locations.
Vikas Lokhande@vlokhande
avatar
Detections.ai Community
3 months ago
17035