A FortiSIEM correlation rule fires when five failed SSH logins occur within 60 seconds from the same source IP. Which attack stage does this rule primarily detect?
-
A
Credential brute-forcing
-
B
Lateral movement via pass-the-hash
-
C
Data exfiltration over SSH
-
D
Command-and-control beacon check-in