Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-WEL-LAB-001Easy
Browser LabLD-WEL-LAB-001Easy15 min

Authentication Investigation

Overnight Security-log events from a Jisr host. Determine which account was brute-forced into and how the attacker connected.

What you will be able to do

  • Read 4625/4624 and LogonType to find a takeover.
  • Distinguish a brute-force success from a lone typo.
Windows SecurityIncident TriageT1110Brute Force

Sign in to start this lab.

Sign in