Detection rules › By eventMicrosoft-Windows-Security-Auditing event 46484 detection rules reference this event. View event page.Sigma (1)Suspicious Remote Logon with Explicit Credentials severity medium T1078 Splunk (3)Windows Identify PowerShell Web Access IIS Pool T1190 Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials T1110.003 Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials T1110.003