mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
detection testing
This commit is contained in:
+1
-1
@@ -2,7 +2,7 @@ name: High Number of Login Failures from a single source
|
||||
id: 7f398cfb-918d-41f4-8db8-2e2474e02222
|
||||
version: 1
|
||||
date: '2020-12-16'
|
||||
description: This search will detect more than 5 login failures in Office365 Azure Active Directory from a single source IP address. Please adjust the threshold value of 5 as suited for your environment.
|
||||
description: This search will detect more than 5 login failures in Office365 Azure Active Directory from a single source IP address. Please adjust the threshold value of 5 as suited for your environment. Deprecated because duplicate.
|
||||
type: ESCU
|
||||
author: Bhavin Patel, Splunk
|
||||
search: '`o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon app=AzureActiveDirectory
|
||||
Reference in New Issue
Block a user