Dikshant Lather · Sep 25, 2026 Detecting Brute Force Attacks Followed by Successful Logon in Microsoft Sentinel Correlate failed sign-ins followed by a successful authentication within a short time window to immediately flag compromised user accounts. Incident Response 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Detecting MFA Fatigue and Push Notification Bombing in Microsoft Entra ID Catch MFA push notification bombing attacks where attackers trigger repeated authentication requests until the victim accidentally approves access. Identity Security 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Hunting for Impossible Travel and Anomalous Token Sign-Ins in Sentinel Detect geographic anomalies, session cookie theft, and impossible travel patterns across cloud user logins using geospatial distance calculation functions in KQL. Identity Security 2 min read 0 0