logo

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

ID: d0340f10-7157-5d77-b36e-f227ee464bf7

STIX ID: report--d0340f10-7157-5d77-b36e-f227ee464bf7

Feed Name: SANS ISC Diary

Threat Score
40/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

...
...

A hands-on diary demonstrating how to use Microsoft Graph PowerShell (e.g., `Get-MgAuditLogSignIn`) to review Entra/Azure AD sign-in logs, filter for failed or successful logins, extract geo-location and failure reasons, and detect suspicious activity such as password-spray attacks and logins from unexpected countries; the author shows example queries and notes using findings to tighten conditional access policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.