Ransomware Series: Valid Account Abuse via Infostealer-Sourced VPN/RDP Credentials
This rule detects successful authentication events for remote access applications (VPN, RDP, Azure AD App Proxy) where the source IP address or ASN has not been observed in the user's login history within the preceding 14 days. This behavior is indicative of potential account takeover using compromised credentials sourced from infostealers or other credential-harvesting activities.
Microsoft Sentinel (KQL)

