Vikas Lokhande
@vlokhande0 followers1 download24 copies0 likes329 views
1 detection
Filters
Last updated
All Time
Detection languages
1
Categories
1
1
1
Platforms
1
1
Products / Services
1
1
1
MITRE Techniques
1
1
1
1
1
This rule detects successful sign-in events originating from IP addresses that have previously demonstrated a password-spraying pattern (multiple failed sign-ins across distinct accounts within a two-hour window). To reduce noise, it excludes successful logins originating from 'known' Autonomous System Numbers (ASNs) where at least 10 distinct users have historically authenticated successfully. The detection further filters for sessions lacking managed device identifiers and allows for manual exclusion of specific applications, IP addresses, or geographic locations.