detection testing

This commit is contained in:
P4T12ICK
2021-01-18 15:46:53 +01:00
parent 44bf41a678
commit 477221da99
6 changed files with 1 additions and 1 deletions
@@ -2,7 +2,7 @@ name: High Number of Login Failures from a single source
id: 7f398cfb-918d-41f4-8db8-2e2474e02222
version: 1
date: '2020-12-16'
description: This search will detect more than 5 login failures in Office365 Azure Active Directory from a single source IP address. Please adjust the threshold value of 5 as suited for your environment.
description: This search will detect more than 5 login failures in Office365 Azure Active Directory from a single source IP address. Please adjust the threshold value of 5 as suited for your environment. Deprecated because duplicate.
type: ESCU
author: Bhavin Patel, Splunk
search: '`o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon app=AzureActiveDirectory