Tag
A detection rule identifies potentially compromised accounts by aggregating multiple high-risk security alerts associated with the same user ID within a four-hour window.