KnockKnock attack targets Office 365 corporate email accounts - It's time to audit failed login activities in your Office 365
Researchers uncovered KnockKnock, an attack on Office 365 Exchange Online email accounts, originating from 16 countries around the world.
KnockKnock targeted on automated corporate email accounts not tied to a human identity, which often lacked advanced security policies like no MFA and no recurring password reset.
May be. You need to monitor failed login activities regularly to know whether you are under any security threat.
You can go to audit log option available in security & compliance center and search for failed login attempts. but it's very difficult to search and find as O365 produce huge audit data.
You can find the demo of the dashboard here.
Note: This post was originally published in o365reports.com