Failed Login Attempt by Expired account

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query looks at Account Logon events found through Windows Event Id's as well as SigninLogs to discover login attempts by accounts that have expired.

Attribute Value
Type Hunting Query
Solution Standalone Content
ID 562900b1-39c4-4baf-a050-9cad1641db35
Tactics InitialAccess
Techniques T1078
Required Connectors AzureActiveDirectory, SecurityEvents
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/MultipleDataSources/LogonwithExpiredAccount.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries