Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

Summary

The article emphasizes the importance of reviewing logs, particularly those related to Entra (formerly Azure AD) logins, after migrating to the cloud. It highlights the need to analyze successful and failed login attempts, drawing parallels to the log monitoring practices common in on-premise environments.

IFF Assessment

FRIEND

This article encourages defenders to review their security logs, which is a crucial defensive practice for identifying suspicious activity.

Defender Context

Cloud adoption often leads to a neglect of essential log monitoring practices. Defenders should prioritize reviewing Entra login logs to detect potential brute-force attacks, password spraying, and unauthorized access attempts that might otherwise go unnoticed in cloud environments.

Read Full Story →