As we've seen with recent attacks, it may be worthwhile to track and monitor login attempts and failures. In the video, How To Audit Login Failures, we look at techniques of how to accomplish this with T-SQL. Keep in mind that this will not filter for false alerts and a sophisticated attacker may mimic what appears to be legitimate activity (ie: a password reset) to blow up this log - this is one of many reasons why password resets themselves can be dangerous.
Some questions that are answered in the video:
- What are 2 techniques that we can use for identifying recent login failures?
- What is 1 way that we can track login failures?
- What is an example scenario of where tracking this information may be helpful?
- Using the functionality, what are some useful parameters to know?
For mastering data transformation from one form to another form, check out the highest-rated Automating ETL course on Udemy. For a coupon to the course, check out the trailer video on the channel SQL In Six Minutes.
One very important consideration to make with designs such as this is What Everyone Should Know About Hackers - Who and Why. We must stop and consider who we're trying to stop before designing any monitoring, spoofing or counter-attack architecture. This may be a poor design relative to our opponents. The same is true for monitoring. While it may seem to be useful, if these attacks from some sources that are then leaked, we may be exposed to more damages. One should be extremely strategic in cybersecurity.
Are you looking for tech consultants that can assist with design and development? From building custom applications to working with existing infrastructure that's causing you trouble, we can get you connected to consultants who can assist. You can contact for assistance.
SQL In Six Minutes (YouTube) | SQL In Six Minutes (Odysee) | Automating ETL | T-SQL In 2 Hours | Consumer Guide To Digital Security