Skip to content

Repository files navigation

🛡️ Windows Brute Force Detection Dashboard (Splunk)

This project helps you build a Splunk dashboard to detect brute-force login attempts in a Windows Active Directory lab environment.

You'll learn how to:

  • Create a Splunk dashboard
  • Add custom panels using SPL queries
  • Visualize failed logins, attack sources, and suspicious PowerShell usage

dashboard


📦 What's Included

  • Step-by-step guide to create the dashboard in Splunk
  • Prebuilt SPL queries for:
    • Top failed login IPs
    • Most targeted usernames
    • Failed logins over time
    • Brute force success detection
    • PowerShell -NoProfile execution

🧪 Lab Context

The dashboard is designed for homelab use and tested with:

  • Simulated brute-force attacks (e.g., using Hydra)
  • PowerShell post-exploitation activity
  • Atomic Red Team techniques

✅ How to Use

  1. Make sure your Windows logs (4624, 4625) are forwarded to Splunk
  2. Follow the setup guide to create a dashboard and add panels
  3. Paste the SPL queries into each panel
  4. Simulate attacks to see the dashboard in action

📎 Reference

About

Dashboard for detecting brute force attacks in Splunk

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors