Password spray signature targeting manager/senior accounts by source IP

This rule detects a password-spraying attack pattern directed at privileged or manager-titled accounts. It monitors for multiple failed sign-in attempts from a single source IP address against a large volume of distinct user accounts identified as managers or senior staff. The detection logic filters for low-frequency attempts per account, which is indicative of a distributed spray attack designed to evade account lockout thresholds while focusing on high-value targets.