Hi,
I'm searching for posibilites to create a sensor that is monitoring the Azure Active Direcory account on failed logins.
So far i only found a posibility to log failed login attemps from the windows event viewer (https://www.paessler.com/manuals/prtg/event_log_windows_api_sensor) But in my opinion, this sensor is monitoring it from the wrong side. This sensor only shows failed logins on the devices that we have, missing the most important thing i'm looking for (showing failed logins from places and devices outside of our organisation)
Long story short, I want to create a sensor with these spec but i don't know how - Failed account login, monitored from the accounts - I want to see hacking attemps on the accounts - I prefer the monitoring of Azure AD accounts.
Add comment