RDP Brute Force/Password Spray Followed by Successful Logon
This rule detects a credential-based attack where a single source IP performs multiple failed RDP (LogonType 3/10) attempts against various user accounts, followed by a successful authentication from the same source within an hour. This pattern is indicative of password spraying or brute-forcing followed by successful lateral movement via Remote Desktop.
CQL

