This playbook is designed to respond to incidents involving brute-force login attempts. It enriches the incident with user and computer information from Microsoft Active Directory (AD), allows for a manual analyst decision, and automatically executes actions like user disablementand case closure through ArcSight SOAR.
This playbook is designed to respond to incidents involving brute-force login attempts. It enriches the incident with user and computer information from Microsoft Active Directory (AD), allows for a manual analyst decision, and automatically executes actions like user disablementand case closure through ArcSight SOAR.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox