Hi Team ,How to write Yara-L rule to detect this .
* Unusual IP - This IP address has not or has rarely been seen in last 30 days.
* Unusual Geo - The IP address, city, country and ASN have not (or rarely) been seen in last 30 days.
* New user & New Device - A new user logs in from an IP address and geo location, and device which are not expected to be seen in the last 30 days.