Tristan’s Cybersecurity Substack

Tristan’s Cybersecurity Substack

SIEM / SOC / MDR

SIEM 103 — Detect Windows bruteforce part 2

Tristan Dostaler's avatar
Tristan Dostaler
Jun 04, 2022
∙ Paid
Upgrade to paid to play voiceover

SIEM 103 — Detect Windows bruteforce part 2

This post is a follow up of the post SIEM 102 — Detect Windows bruteforce where I explained how to create a detection Use Case to detect a Windows bruteforce.

In this post I will explain how we can enhance the original detection logic by having a lower False Positive rate.

As I explained in the last section of the initial post, it is important to manage False Positives (FP). In the past few months, I spent some time to look for ways to reduce FP and this post will summarize them.

User's avatar

Continue reading this post for free, courtesy of Tristan Dostaler.

Or purchase a paid subscription.
© 2026 Tristan Dostaler · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture