threat-intel Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st) This article details a method for identifying password spray attacks and unusual login activity within Microsoft Entra (formerly Azure Active Directory) logs. By analyzing login events and filtering for unexpected countries and failed logins, security analysts can proactively detect and mitigate password spraying attac… SANS Internet Storm Center · Aug 21, 2026 Medium entragraphpassword sprayconditional access