Ransomware TTP Series: SSL VPN Credential Spraying Without MFA (Akira)

Detects anomalous authentication behavior originating from a single source IP targeting an SSL VPN gateway. The rule identifies a high volume of unique usernames failing authentication within a short time window, a pattern indicative of password spraying and often associated with initial access attempts on environments lacking multi-factor authentication (MFA), such as those leveraged in Akira ransomware operations.