Active Directory attack detection with Splunk SIEM — RDP brute force detection, Event ID 4624 correlation, and SOAR automation via Shuffle and Slack
splunk active-directory cybersecurity siem soc soar blue-team homelab-automation rdp-detection event-id-4624
-
Updated
Jul 7, 2026