Potentially Suspicious Explicit Credential Local Logon — Detection Rule

Detects potentially suspicious explicit credential logon events where the user is trying to logon with explicit credentials (username and password) that are different from the current user context. It might indicate an attacker attempting to escalate privileges after obtaining credentials for a different user account.

Read the full analysis on IntelFusions