Access request for the same account with multiple passwords in a given time span (brute force)
Call is successful but invalid scope was provided
Out of the ordinary number of valid requests
Valid tokens are trying to access operations that don't exist
IPs trying to access services/endpoints that don't exist
An unusual number of requests to a sensitive operation from a single user
Response contains PII