Azure Portal brute force login
Incident Management is now generally available! Incident Management is now generally available!
<  Back to rules search

Azure Portal brute force login

azure

Classification:

attack

Tactic:

Technique:

Set up the azure integration.

Overview

Goal

Detect when a user is a victim of an Account Take Over (ATO) by a brute force attack.

Strategy

Monitor Azure Active Directory Sign-in logs and detect when any @evt.category is equal to SignInLogs, and @evt.outcome is equal to failure.

Triage & Response

  1. Inspect the log and determine if this was a valid login attempt.
  2. If the user was compromised, rotate user credentials.