A SOC analyst is reviewing logs in a SIEM and notices multiple failed login attempts followed by a successful one from an unknown IP. Which specific IoC category does this activity represent?
Failed logins followed by success is a common IoC for unauthorized access.
Why this answer
This behavior is a classic indicator of a brute-force attack or credential stuffing attempt.