Windows EDR - Logon Auditing
next quarter
C
Chris Bareham
This will be helpful, as it would add the capability to track the logon/logoff without needing to enable the Windows Event Logs. As long as it will also include the failed logins to detect brute force attempts.
R
Ruben Castello
Brute force attacks are detected with that?
M
Marc Wilhelmi
Please also recognize & report brute force attempts
J
Joshua Nikolson
Hopefully this will work smoothly with computers that are Entra ID (AAD) joined as logons are somewhat different
James Mason | SE @ Huntress
marked this post as
next quarter