Credential stuffing burst against login endpoint
Detects a high volume of HTTP POST requests to common login endpoints (e.g., /login or /wp-login.php) from a single source IP address within a short time frame, which is indicative of a credential stuffing or automated brute-force attack.
Suricata

