// Investigation

Detection engineering

Correlation rules evaluated against the event stream. Disabling a rule stops it raising alerts but preserves the alerts it has already produced.

19rules19armed1ATT&CK tactics covered

Rule library

1 of 19 rules shown

ArmedRuleSeverityCategoryATT&CKAlerts
Password spray against directory services

One source address failing authentication repeatedly inside a short window, consistent with spraying a common password across many accounts.

HighCredential Access
T1110.003Credential Access
1