how to work on suspicious login attempts detected incident in sentinel

Mohd Hussain 0 Reputation points
2023-02-25T13:43:22.0933333+00:00

how do i work on Suspicious login attempts detected in sentinel .

Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Bill Clarkson-Antill 15 Reputation points MVP
    2023-03-14T21:05:47.4933333+00:00

    Hey

    Depending on your environment, theres a number of factors that will help you in regards to viewing, detecting and working on Suspicious login attempts.

    First is your Sentinel ingesting Identity protection logs and/or Microsoft Defender for Identity logs etc, if so there will be a new table that is generated within Microsoft sentinel for suspicious login attempts across your Microsoft based infrastructure. If you are wanting to monitor from bespoke sources then ingesting data in from these sources and identifying unusual activity i.e brute force etc. Custom alerting will need to be created for these types depending if they are Microsoft supported or not

    Hope this helps, if you need more information, please reach out

    Regards

    Bill

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.