A SOC team wants to build a playbook for credential stuffing attacks. Which data source should be the PRIMARY trigger for this playbook?
-
A
Firewall rule change alerts
-
B
Multiple failed login attempts followed by a successful login from an unusual geography
-
C
Antivirus quarantine notifications
-
D
DNS sinkhole traffic logs