I'm not convinced about the relevancy of the "UserLoginFailed" events.
That would seem to lead to false positives.
For instance, even if an account is genuinely unused, but some botnet is trying a brute force attack, it's going to flood this script with entries that get erroneously counted as user activity.
I'm not convinced about the relevancy of the "UserLoginFailed" events.
That would seem to lead to false positives.
For instance, even if an account is genuinely unused, but some botnet is trying a brute force attack, it's going to flood this script with entries that get erroneously counted as user activity.