Credential Stuffing Sign-In Success
Detects an authentication pattern characteristic of credential compromise, consisting of a burst of failed authentication attempts against an account within a short window, followed immediately by a successful sign-in from an anomalous or new device/location. This pattern is indicative of brute-force or credential spraying followed by successful validation and potential lateral movement.
Microsoft Sentinel (KQL)

