LoFP LoFP / t1201

t1201

TitleTags
a user with more than 20 failed authentication attempts in the span of 5 minutes may also be triggered by a broken application.
administrators or power users may use this command for troubleshooting.
commonly used by administrators for troubleshooting
legitimate administration activities
legitimate powershell scripts
while this search has no known false positives, it is possible that an aws admin has legitimately triggered an aws audit tool activity which may trigger this event.