SOP-02: Brute Force & Credential Stuffing Response

Analyst playbook for brute force and credential stuffing alerts. Covers spray vs brute classification via KQL, success-after-failure compromise detection, Entra ID Named Locations IP block, and Identity Protection risky user actions.

2026-06-15T03:10:09.569Z
Rudra Verma, Senior Security Architect & Researcher