news.mlab.sh
Back to the feed
threat-intel

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

Medium
Image: SANS Internet Storm Center
Summary

This article details a method for identifying password spray attacks and unusual login activity within Microsoft Entra (formerly Azure Active Directory) logs. By analyzing login events and filtering for unexpected countries and failed logins, security analysts can proactively detect and mitigate password spraying attacks, ultimately strengthening Entra security posture. The author successfully used this technique to help a client improve their conditional access policies.

Read the full article at SANS Internet Storm Center

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.