CVE-2026-88771/88772 NetScaler Risky Signin+VPN+Connection Burst Chain

This rule detects potentially compromised accounts by correlating risky Entra ID sign-ins to Citrix NetScaler with subsequent VPN session establishment followed by rapid, high-volume outbound connection activity from the source IP address. This pattern is indicative of a threat actor using compromised credentials to gain access via VPN and immediately perform internal network scanning or data staging.