logo

Geopolitical Cyber-Detection Lures for Attribution with Microsoft Sentinel 

ID: ed7932ea-ff2f-5f31-aa02-057c40892d48

STIX ID: report--ed7932ea-ff2f-5f31-aa02-057c40892d48

Feed Name: Black Hills Infosec Blog

Date Published: 2022-05-17

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post demonstrates how to use Microsoft Sentinel with Log Analytics to rapidly profile brute-force activity against internet-exposed RDP and SSH services by querying Windows EIDs 4624/4625 and Syslog 'Failed password' messages via shared KQL; it shows attacks ramp up within an hour, often sourcing RDP attempts from Russian IP ranges and SSH from Southeast Asia, and recommends building geo-heatmaps and using the findings to guide network blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.