Dikshant Lather · Sep 25, 2026 Detecting Brute Force Attacks Followed by Successful Logon in Microsoft Sentinel Correlate failed sign-ins followed by a successful authentication within a short time window to immediately flag compromised user accounts. Incident Response 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Hunting for Kerberoasting Attacks via Kerberos Service Ticket Requests (Event ID 4769) Uncover Kerberoasting attacks targeting Active Directory Service Principal Names (SPNs) using KQL anomaly detection on Windows Security Event ID 4769. Active Directory Security 2 min read 0 0