Мылору
If you still think there is a bruteforce possibility or you want to report a bruteforce scenario in a different project with it's own authentication, report must be based on the test with a real successful attempt and should include full scenario of account registration and bruterofce attack, exact number of logon attempts of different types, timings, dictionary sizes, password/codes patterns (or dictionary attached as a file), etc. Burp logs, videos, calculations without real tests etc can not replace this information. Demonstration for test account with given password pattern or phone number may be requested by security team.