Geopolitical Cyber-Detection Lures for Attribution with Microsoft Sentinel
ID: ed7932ea-ff2f-5f31-aa02-057c40892d48
STIX ID: report--ed7932ea-ff2f-5f31-aa02-057c40892d48
Feed Name: Black Hills Infosec Blog
This blog post demonstrates how to use Microsoft Sentinel with Log Analytics to rapidly profile brute-force activity against internet-exposed RDP and SSH services by querying Windows EIDs 4624/4625 and Syslog 'Failed password' messages via shared KQL; it shows attacks ramp up within an hour, often sourcing RDP attempts from Russian IP ranges and SSH from Southeast Asia, and recommends building geo-heatmaps and using the findings to guide network blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
