// Investigation
Detection engineering
Correlation rules evaluated against the event stream. Disabling a rule stops it raising alerts but preserves the alerts it has already produced.
19rules19armed1ATT&CK tactics covered
Rule library
1 of 19 rules shown
| Armed | Rule | Severity | Category | ATT&CK | Alerts |
|---|---|---|---|---|---|
| Password spray against directory services One source address failing authentication repeatedly inside a short window, consistent with spraying a common password across many accounts. | High | Credential Access | T1110.003Credential Access | 1 |