Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays
Executive Summary
The article discusses how security teams can use PowerShell scripts to analyze Azure Entra login logs, highlighting best practices, common pitfalls, and detection of password spray attacks. It emphasizes the importance of reviewing logs after migrating to the cloud and provides actionable guidance for identifying suspicious login patterns.
Intelligence Metadata - Source Publisher: SANS Internet Storm Center - Published Date: 2026-08-21T01:49:18+00:00 - Category: threat-intel
Original Description: One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise.
"Sooner or later, those who win are those who think they can."
— Richard Bach
Source: SANS Internet Storm Center